Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OPT interface exit route nightmare

    Scheduled Pinned Locked Moved Routing and Multi WAN
    13 Posts 4 Posters 1.3k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mike315
      last edited by

      Like this one ?

      Int : WAN2
      Source : GUEST network
      source : *
      dest : *
      dest port : *
      NAT addr : WAN2 interface address
      NAT port : *

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        Yes.

        1 Reply Last reply Reply Quote 0
        • johnpozJ Online
          johnpoz LAYER 8 Global Moderator
          last edited by

          Is that wan2 nat being applied? Do a simple sniff on your wan2 - when you send traffic to say your wan2 gateway from this guest client which you say works is pfsense natting this to its wan2 IP?

          Can pfsense using wan2 get to the itnternet?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07 | Lab VMs 2.8, 25.07

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Post your GUEST rules.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • M Offline
              mike315
              last edited by

              Thx @viragomann, now that I've added the NAT rule, it's working !
              I still don't know why this NAT rule is needed though... Isn't the interface supposed to forward the traffic to the default gateway / or rule specific gw ?

              1 Reply Last reply Reply Quote 0
              • johnpozJ Online
                johnpoz LAYER 8 Global Moderator
                last edited by

                If it doesn't NAT it how does the upstream know how to get back to this downstream network. You wuldn't have to nat it if your upstream knew how to get back to this network.

                If your wan2 is public - then yeah for sure it has to be natted, since rfc1918 doesn't route on the internet.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07 | Lab VMs 2.8, 25.07

                1 Reply Last reply Reply Quote 0
                • V Offline
                  viragomann
                  last edited by

                  @mike315 said in OPT interface exit route nightmare:

                  I still don’t know why this NAT rule is needed though… Isn’t the interface supposed to forward the traffic to the default gateway / or rule specific gw ?

                  You have to distinguish routing and NAT.
                  If your internet router have no static route to your guest network behind pfSense, you have to do NAT on outbound traffic.
                  If the outbound NAT work in automatic mode, the necessary rules should be added by pfSense automatically, but sometimes that fails.

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    mike315
                    last edited by

                    @viragomann

                    But my internet router has a static route to my guest network, with pfsense as a GW...

                    1 Reply Last reply Reply Quote 0
                    • DerelictD Offline
                      Derelict LAYER 8 Netgate
                      last edited by

                      What?

                      Draw a diagram. Please be specific and complete.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • V Offline
                        viragomann
                        last edited by

                        If it has a route for the guest network pointing to pfSense NAT shoudn‘t be needed. Maybe therer is something wrong with it.
                        Since you have 2 WANs, does the route point to the right address?

                        1 Reply Last reply Reply Quote 0
                        • M Offline
                          mike315
                          last edited by

                          Ok, it's working now that I've disabled the NAT rule, not sure what was wrong before...

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.