Single WAN connection with two public IP subnets / ranges (version 2.0.3)
-
Normally, people would connect to the network, usually by bridging to it and then they would set up virtual IPs and use 1:1 NAT but I'm not sure this will apply with your setup.
-
Setup the first subnet normally on the WAN interface. For the second subnet, manually add a gateway under System > Routing > Gateways on the WAN interface. Then you can simply add virtual IP addresses of type "IP Alias" from the second subnet on WAN interface.
After that create Manual Outbound NAT rules for that Virtual IP address if you want to NAT clients behind that address. You can also do 1:1 NAT against the virtual IP addresses.
You'll need to create/modify firewall rules to use the second gateway wherever necessary.
-
Ahhhh - That makes sense.
-
@KurianOfBorg:
Setup the first subnet normally on the WAN interface. For the second subnet, manually add a gateway under System > Routing > Gateways on the WAN interface. Then you can simply add virtual IP addresses of type "IP Alias" from the second subnet on WAN interface.
After that create Manual Outbound NAT rules for that Virtual IP address if you want to NAT clients behind that address. You can also do 1:1 NAT against the virtual IP addresses.
You'll need to create/modify firewall rules to use the second gateway wherever necessary.
Thanks! I will try this approach over the coming weekend.
-
Hi, I'm in the very same situation as DallasITGuy.
Adding a second gateway to WAN via the pfSense web gui doesn't work because "The gateway address xx.xx.xx.xx does not lie within the chosen interface's subnet."
How can I solve?
Thanks -
I don't have access to my box to check right now, but I think only some particular kinds of Virtual IP addresses can be used for routing. Try something other than IP Alias.
-
@KurianOfBorg:
I don't have access to my box to check right now, but I think only some particular kinds of Virtual IP addresses can be used for routing. Try something other than IP Alias.
I tried Proxy ARP and Other but it doesn't work.
Let me give you some details about my setup:pfSense has 2 NICs: LAN (10.0.0.1/24) and WAN (46.x.x.1/26). 46.x.x.gw is my Default Gateway. Additional public ips from 46.x.x.x/26 are configured as "IP ALIAS" and then used for 1:1 NAT.
Today my ISP gave me another /26 public ip subnet (47.x.x.0/26) which gets routed to my WAN interface by their routers, but they also give me a second gateway (47.x.x.gw/26).How should I add ips from the second public subnet while keeping one single WAN interface? Should I continue using the first gateway (46.x.x.gw)?
Thanks
-
You cannot use the first gateway for the second public subnet. If you are unable to add virtual IP address from different subnets and add a different gateway, then you only option is to create a second WAN interface.
-
I just did a test and I am able to successfully add a new virtual IP address of type IP alias and gateway in a new subnet different from the interface IP address and gateway.
-
@KurianOfBorg:
I just did a test and I am able to successfully add a new virtual IP address of type IP alias and gateway in a new subnet different from the interface IP address and gateway.
Hi,
I managed to add new VIPs from a different WAN subnet without even adding a new gateway.After turning pfSense config upside down so many times, I realized to have mistyped an entry in the routing table, that's why my VMs were not responding. Now it's all up and running. :-[
Thanks