Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Public ip behind pfsense

    Scheduled Pinned Locked Moved Routing and Multi WAN
    12 Posts 4 Posters 5.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nelioromao
      last edited by

      This a more realist Sample

      Suppose ISP provides a public IP subnet 211.100.200.152/255.255.255.248
      gw: 211.100.200.158

      The public IP addresses we can use are between 211.100.200.153 to 211.100.200.157.

      non-NAT subnet so that the server behind pfsense  can use the public IP address 211.100.200.154.

      1 Reply Last reply Reply Quote 0
      • K
        kpa
        last edited by

        Your ISP doesn't have a clue  ::)

        That subnet is terminated at their own router which means that the only way you can use public IPs on your systems and have pfSense between the systems and the ISP router at the same time is to use a filtering bridge.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          or setup 1 to 1 nat with vips in that range to rfc1918 behind pfsense.

          That is not a routed network to you.. That is just hung off their network.  The only way you can use that without natting is to bridge it like kpa mentions.

          A routed network would be something like say.

          211.100.200.152/30 as the transit.. where say your pfsense box is .153 with gateway of .154.. And then they routed 211.100.200.160/29 too that 211.100.200.153 address then you could put the 211.100.200.160/29 behind pfsense without nat.  Where pfsense would be say .161 on its interface and then your boxes behind would be .162 to .166 with their gateway being pfsense .161 address.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • N
            nelioromao
            last edited by

            Tank you  PFsense team

            I Find something else hear with the setup but is a old post.
            Will this work on 2.3.3 pfsense release :o

            https://forum.pfsense.org/index.php?topic=104528.msg582816#msg582816

            Seams like the solution is to bridge

            Tank you
            Any further ideas/solutions will be appreciated :)

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              I wouldn't call a bridge a solution.. I would call it a work around to make it work ;)  If you can not true routed network.

              What are you trying to do that natting is not a solution to your problem.. Just create your vip, create your 1to1 and now just work with pfsense with normal firewall rules, etc.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • T
                TeknikL
                last edited by

                I run several subnets behind pfsense in routed mode (no nat rules) and it works fine. make sure the routed subnet is a different interface than your NATted LAN interface, that helps.

                1 Reply Last reply Reply Quote 0
                • N
                  nelioromao
                  last edited by

                  :) Nice to know that Tank you.

                  • Can you give some details how you have you setup for that.

                  • For the moment i im using the  bridge solution. not the best setup.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Dude you can not run the networks behind pfsense unless they are actually ROUTED TO YOU!!  If they are routed to you, then you would do it just like any other network you create on pfsense.. You would just turn off nat.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • N
                      nelioromao
                      last edited by

                      8). Yes you are 100% write.  That is what i have just done. and works very good.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        What works very good what you stated what you had /29 that you were connected too - no networks routed to you from your statements.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.