Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Providing NAT to a LAN behind the LAN interface

    Scheduled Pinned Locked Moved NAT
    12 Posts 2 Posters 738 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mspies
      last edited by

      download.png Drawing

      I quickly whiteboarded this to get you a quick answer on the drawing.

      It is not routed through a transit network, unless I am wrong with how I define a transit network. As you can see in the drawing, these two local networks sit on 1 router.

      Not sure where the asymmetrical routing would come in as these networks only have a single path.

      Thanks for the prompt reply.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Do you have hosts on this 10.91.0.128/29 network that your wanting to talk to or from your downstream network?

        What rules do you have on the .129 interface?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • M
          mspies
          last edited by mspies

          Only hosts are pfSense and the router.

          I am still getting the hang of pfSense, what rules are you referring to?

          Under Firewall>Rules>LAN I have a list of addresses that can access 22 and 443 from both 10.91.0.128/29 and the 192.168.73.0/24 networks. Along with a block on 22 and 443 from any. Other rules I believe are the default rules on the firewall, allow LAN to any and allow LAN IPv6 to any.

          Firewall>Rules>LAN:

          Annotation 2020-01-03 154245.png spoiler

          ManagementAccess:

          Annotation 2020-01-03 154409.png

          ManagementPorts:

          Annotation 2020-01-03 154350.png

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            That is the rules for the 10.91.0.129 interface? Your lan in pfsense"

            So while those rules would allow access to your management ports from your downstream 192.168.73/24 network your other rules do not allow your downstream to go anywhere - only the lan net which is your /29 only.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • M
              mspies
              last edited by

              Thanks. That has been driving me crazy all day.

              Another question, you seem surprised by my seemingly lack of rules on the LAN, why? (Or I am massively mis-reading what your first line is to mean there.)

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Not surprised.. just wanted to validate you were showing the correct interface.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • M
                  mspies
                  last edited by

                  I see what you mean, terrible capture on my part.

                  Thanks again for the quick resolution!

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    glad you got it sorted.. Just remember in such a setup if you put any sort of devices/hosts on that /29 you would need to do host routing on them... Or your going to run into asymmetrical routing.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • M
                      mspies
                      last edited by

                      This is a test bed before I move this into a more production environment. I will probably end up with the pfSense to router connection being a smaller subnet to completely avoid that scenario.

                      Curious though, where would the asymmetrical routing come from? This is my first major dive into this sort of networking detail and just want to know what the downfall of that would be.

                      Thanks.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        So if host say on .131 wants to talk to 73.x he hits pfsense as his gateway... Which pfsense sends to .130, but return traffic will just go straight to .131 So now you are asymmetrical

                        If 73.x is wanting to talk to say .131 on your /29 no need to send to pfsense, so pfsense never see syn, and the syn,ack the .131 box would send back via pfsense would be out of state and pfsense would not allow the traffic, etc..

                        You would have to be natting on your downstream, or do host routing to prevent such things.. Its best to just use it as pure transit and not put any hosts on it..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.