Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Nating from Wan1 to Wan3

    Scheduled Pinned Locked Moved NAT
    23 Posts 2 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      doktornotor Banned
      last edited by

      Let me clarify:

      So, you have some webserver (???) running on port 8080 which is only accessible via the (unknown flavour of) VPN with RFC1918 (non-public) IP? And you are trying to access that from public IP space via the (at least) triple NAT (modem -> WAN1 -> OpenVPN)?

      1 Reply Last reply Reply Quote 0
      • I
        InserTec
        last edited by

        Yes, is correct.

        ExternalIp-Modem -> Wan1 -> (Pfsense) -> Wan3 (Cisco) by vpn tunnelled ip nated 192.168.15.1 <-> 10.14.64.33

        Thanks very very much for your time.

        I attach the rule from lan to 8080 server working ok.-
        I need from external ip Wan1 access to this server.-

        ![Captura de pantalla 2015-06-03 a la(s) 12.18.25.png](/public/imported_attachments/1/Captura de pantalla 2015-06-03 a la(s) 12.18.25.png)
        ![Captura de pantalla 2015-06-03 a la(s) 12.18.25.png_thumb](/public/imported_attachments/1/Captura de pantalla 2015-06-03 a la(s) 12.18.25.png_thumb)
        ![Captura de pantalla 2015-06-03 a la(s) 12.18.34.png](/public/imported_attachments/1/Captura de pantalla 2015-06-03 a la(s) 12.18.34.png)
        ![Captura de pantalla 2015-06-03 a la(s) 12.18.34.png_thumb](/public/imported_attachments/1/Captura de pantalla 2015-06-03 a la(s) 12.18.34.png_thumb)

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          Can you bridge that modem on WAN1 to get rid of at least one level of NAT?

          1 Reply Last reply Reply Quote 0
          • I
            InserTec
            last edited by

            Now is not possible bridge the modem  :-[, only i can make a dmz

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              Is manual NAT (port forward) possible on the modem?
              What kind of VPN are you using for the LAN-to-LAN VPN?

              I do think this kind of setup is meaningful, or reliable, or anything even remotely close to sane state… Good luck.

              1 Reply Last reply Reply Quote 0
              • I
                InserTec
                last edited by

                Yes is posible.
                Now i have configurate a dmz to 192.168.2.2, can i disable and make a manual port forward.

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  What's the VPN?

                  1 Reply Last reply Reply Quote 0
                  • I
                    InserTec
                    last edited by

                    I not understand the question.

                    The vpn work fine and joins two buildings with other ftth lines.
                    I only have access to lan of cisco, in 192.168.15.1 as gateway and go correctly to 8080 server in the ip of other building 10.14.64.33.

                    Sorry my english is horrible and in the vpn im very limited. I only hace access to 192.168.15.x and 192.168.15.1 as gateway to go to the server port 8080.

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      @InserTec:

                      I not understand the question.

                      OpenVPN? IPsec? PPTP? Something else? Or, the VPN is not on pfSense at all?

                      Well, maybe someone else. There's also Spanish subforum here.

                      1 Reply Last reply Reply Quote 0
                      • I
                        InserTec
                        last edited by

                        Vpn Ipsec and not pfsense is a cisco router 891.
                        Is connected from lan of cisco to a lan (hardware rj45) in pfsense and i call wan3.

                        1 Reply Last reply Reply Quote 0
                        • D
                          doktornotor Banned
                          last edited by

                          @InserTec:

                          Is connected from lan of cisco to a lan (hardware rj45) in pfsense and i call wan3.

                          Calling something WAN when it's in fact NOT a WAN really does NOT help. When you say WAN here -> something usable for generic internet access.

                          1 Reply Last reply Reply Quote 0
                          • I
                            InserTec
                            last edited by

                            please, dont bother with me  :'(
                            Yes, this not is a wan… not resolve internet access only a lan in other building.
                            Sorry

                            1 Reply Last reply Reply Quote 0
                            • D
                              doktornotor Banned
                              last edited by

                              As hinted above, perhaps posting in the Spanish subforum would get you better understanding…

                              Provided you can somehow get the traffic across the modem (DMZ, NAT), try with the following NAT rule:

                              Interface WAN1
                              Protocol: TCP
                              Destination: WAN1 Address
                              Destination port 8080
                              Redirect Target IP: 10.14.64.33
                              Redirect target port 8080

                              Now, you also need a static route set up to 10.14.64.0/24 via the "WAN3".

                              https://doc.pfsense.org/index.php/Static_Routes

                              1 Reply Last reply Reply Quote 0
                              • I
                                InserTec
                                last edited by

                                Ok Thanks very much doktornotor.

                                I prepare a post for the spanish forum.

                                Thanks for your time.  :D

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.