Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Nat Rule with An exception

    Scheduled Pinned Locked Moved NAT
    6 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lsurules08
      last edited by

      i want to forward all port 80 traffic to port 3128 on a web filter proxy that has a lan ip address.  the webfilter only has a lan connection to the network so i need that webfilter proxy to be excluded from this nat rule.  does this make any sense?  please let me know if i need to explain better.

      1 Reply Last reply Reply Quote 0
      • M
        mikeisfly
        last edited by

        Just create a rule with the source IP of your proxy and make the subnet mask /32 and put the rule above the nat rule. The first rule that matches wins.

        1 Reply Last reply Reply Quote 0
        • L
          lsurules08
          last edited by

          Genius idea.  you sir are a gentleman and a scholar.

          1 Reply Last reply Reply Quote 0
          • M
            mikeisfly
            last edited by

            Thanks :)

            1 Reply Last reply Reply Quote 0
            • L
              lsurules08
              last edited by

              so just to clarify.  i only need a firewall rule to allow my web filter proxy out to the internet?  i dont have to nat anything correct?

              1 Reply Last reply Reply Quote 0
              • M
                mikeisfly
                last edited by

                I'm not sure about that, seems to be what you need. I was just explaining how to make a rule to bypass your Nat rule.

                If you only want the proxy to be natted on port 80 then you can make that change in the outbound Nat section. By default PfSense will Nat the whole subnet.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.