Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help with Double NAT'ing

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      deaney
      last edited by

      Hi Guys,

      This one is driving me crazy.

      Im trying to have my PFsense VM setup so that my VM's are not on the local lan, they all talk through PFsesne and that handles DNS, DHCP etc… effectively acting as a modem/router inside of my virtual network.

      I only want the one IP on my 192.168.1.0 Subnet from the PFsense machine, I want the VM's to pass all traffic through it.

      I have linked the physcial Nic into the PFsesne VM, it goes out to the gateway.

      I edited the rules but still... none of the VM's on the 172 internal network get any internet access..

      Here are some screenshots.

      Thanks in advance!





      Untitled.jpg
      Untitled.jpg_thumb
      ![2013-05-05 2.jpg](/public/imported_attachments/1/2013-05-05 2.jpg)
      ![2013-05-05 2.jpg_thumb](/public/imported_attachments/1/2013-05-05 2.jpg_thumb)
      ![2013-05-05 23_06_34-se.jpg](/public/imported_attachments/1/2013-05-05 23_06_34-se.jpg)
      ![2013-05-05 23_06_34-se.jpg_thumb](/public/imported_attachments/1/2013-05-05 23_06_34-se.jpg_thumb)
      ![2013-05-05 23_06_56-server .jpg](/public/imported_attachments/1/2013-05-05 23_06_56-server .jpg)
      ![2013-05-05 23_06_56-server .jpg_thumb](/public/imported_attachments/1/2013-05-05 23_06_56-server .jpg_thumb)

      1 Reply Last reply Reply Quote 0
      • P
        podilarius
        last edited by

        For WAN options, do you have it set to block private networks?

        1 Reply Last reply Reply Quote 0
        • D
          deaney
          last edited by

          Hi podilarius,

          Thanks for the reply - no, its left unticked as I knew this would cause issues due to the IP.

          1 Reply Last reply Reply Quote 0
          • P
            podilarius
            last edited by

            NP. Just starting with the basics.
            I would ditch the 1:1 rule for now. That is not doing what you think it is. The AON (automatic outbound NAT) is mapping it to only 1 IP address, the WAN address.
            Looks like you will need to port forward anything else internally.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.