Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help Nat alias /24

    Scheduled Pinned Locked Moved NAT
    7 Posts 4 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      acsoprana
      last edited by

      Hello, I have a rang of valid ips /24, and was wondering if there as my internal lan out with these ips valid on the Internet? type, making a nat 1: 1 in the DMZ to few machines, as are many more is unfeasible to make a nat 1: 1, there is some solution in pfsense that allow me to do this with a / 24 whole without making one by one ??

      grateful for the attention

      1 Reply Last reply Reply Quote 0
      • J
        jdp0418
        last edited by

        I am not entirely sure I follow what you are asking.

        Individual 1:1 NAT statements are called 1:1 for a reason.  You can't alias or range 1:1 NAT.  If you really felt the need to create 255 1:1 NAT statements for the entire /24, I guess you could always try entering that into the config via the command line.

        You can setup a NAT pool and have your LAN use a range of IPs either as round robin or sticky NAT for outbound NAT to the internet.

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by

          You can do a 1:1 NAT from a private /24 to a public /24, with a single 1:1 NAT entry, if that's what you mean.

          1 Reply Last reply Reply Quote 0
          • J
            jdp0418
            last edited by

            Oh, I didn't know that.  Cool.  You learn something new every day. :P

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              You can also do a longer subnet to only 1:1 a portion of the /24 right?

              Like a /27 on 30.40.50.128 so 30.40.50.128 - 30.40.50.159 would be mapped to 192.168.1.128 - 192.168.1.159 ??

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • C
                cmb
                last edited by

                @Derelict:

                You can also do a longer subnet to only 1:1 a portion of the /24 right?

                Like a /27 on 30.40.50.128 so 30.40.50.128 - 30.40.50.159 would be mapped to 192.168.1.128 - 192.168.1.159 ??

                Yep, any subnet size is doable. Network address doesn't have to match between them either, just has to be the same size subnet. So 30.40.50.128/27 - 192.168.1.0/27 is doable too.

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  I thought they had to match.  Learned something new today.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.