Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    1 to 1 NAT for LAN subnet to WAN

    Scheduled Pinned Locked Moved NAT
    18 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      robina80
      last edited by robina80

      viragomann -

      mmm... i dont understand sorry...

      i have only this one WAN ip address assigned to me via my ISP 193.203.70.54 out of there /22 range/subnet

      so do i need more than one WAN ip address for this to work, i could ask for another ip from my ISP?

      AndresCT46 -

      sounds great, i will give it a go and see what happens

      so even if i have one WAN ip address provided by my ISP, i can still create a virtual ip using the same WAN ip address

      also "destination" wouldnt this be there WAN ip address, so only they can access my LAN otherwise everyone can externally?

      thanks a lot guys i really do appreciate it!!!

      A 2 Replies Last reply Reply Quote 0
      • A
        AndresCT46 @robina80
        last edited by

        @robina80

        Is necessary that you have a public IP available.

        You can't use your current IP WAN to generate a virtual IP, your ISP must provide you with an additional public IP.

        When you perform the exercise, please verify that in the rules of your WAN you generate the rule that allows the traffic to the destination you need, otherwise you must generate the rule, this forget to say it previously.

        1 Reply Last reply Reply Quote 0
        • A
          AndresCT46 @robina80
          last edited by

          @robina80

          If you can't acquire an additional public IP, my advice is that you generate an IPSec from your pFsense to your client's UTM

          1 Reply Last reply Reply Quote 0
          • R
            robina80
            last edited by

            Ok so i cant use my current wan ip of my router 193.203.70.54

            So i need to get an additional wan ip from my isp and i cqn use that to create a virtual ip?

            1 Reply Last reply Reply Quote 0
            • R
              robina80
              last edited by

              When you say generate an ipsec, do you mean create an ipsec vpn

              A 1 Reply Last reply Reply Quote 0
              • A
                AndresCT46 @robina80
                last edited by

                @robina80

                Yes, Internet Protocol Security (IPSec VPN)

                1 Reply Last reply Reply Quote 0
                • R
                  robina80
                  last edited by robina80

                  But they would need to create an ipsec there end aswell so the two can talk to eachother ie site to site ipsec vpn

                  Is there no otherway to achieve this

                  A 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann
                    last edited by

                    A GRE tunnel was already mentioned by jonhpoz.
                    No, there is no other way than any kind of a tunnel to achieve that.

                    1 Reply Last reply Reply Quote 0
                    • A
                      AndresCT46 @robina80
                      last edited by

                      @robina80

                      It is correct, your client must also generate an IPSec connection in your UTM to have a secure connection from LAN to LAN.

                      If you intend to generate a NAT through your WAN with destination your entire LAN network, pFsense will not understand the meaning of this NAT and will simply do not anything about it, because pFsense will not have a specific destination to redirect your request.

                      This is the meaning of doing a NAT, this is how pFsense enables connections from the WAN to an internal and specific query service on your LAN.

                      I insist, the best option is generate IPSec in your pFsense and in the UTM of your client.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        You can do 1:1 NAT but since you only have one address you can only do one of them. And that will remove the ability to bind anything else on the WAN address.

                        If they only want to connect to one service, you can port forward:

                        Wan_Address:3389 10.30.0.1:3389
                        Wan_Address:3390 10.30.0.2:3389
                        Wan_Address:3391 10.30.0.3:3389
                        Wan_Address:3392 10.30.0.4:3389
                        etc.

                        As has been said above, A VPN is how this is done. That is what you should insist on. Anything else is pretty much wrong.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 1
                        • R
                          robina80
                          last edited by

                          a GRE tunnel sounds interesting, how do you do that

                          is that with 1 to 1 NAT or via IPsec

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Once you have a tunnel there is no need for 1:1 nat or any nat.. The tunnel is used to route the traffic to get to your network.. The whole POINT to a vpn..

                            If you were going to create a tunnel - there is zero reason not to encrypt it because its going over the public internet.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 1
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.