Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    /30 nat on DMZ

    Scheduled Pinned Locked Moved NAT
    3 Posts 2 Posters 440 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mrjoli021
      last edited by

      Hello,
      I have a /30 connecting to the ISP and a /28 which is my public IP's. The /30 is a private ip just for the connection. I have assigned a public IP on the DMZ. I would like to NAT my LAN traffic with that IP, furthermore I would like any hosts on the DMZ to not be NATED. Not sure how to do this on pfsense. Could someone point me in the right direction?

      Provider 192.168.1.0/30 -> PFSense WAN -> DMZ 1.2.3.4/28
      -------------------------> PFSense LAN -> 10.0.0.0/24

      1 Reply Last reply Reply Quote 0
      • M Offline
        mrjoli021
        last edited by

        I am looking for Outbound NAT setup.
        I have create a Virtual IP for my DMZ network as type other and then network. I have gone ahead and enabled the outbound NAT on the firewall section with the virtual IP and the LAN as the source network.
        I am still not able to ping out the internet.

        S 1 Reply Last reply Reply Quote 0
        • S Offline
          SteveITS Rebel Alliance @mrjoli021
          last edited by

          I don't think it's going to work to have the same public IP subnet on both the router WAN and the DMZ. It won't know where to route. I think you'll need to use 1:1 NAT to forward the IPs to the DMZ servers.

          re: outbound NAT try
          Source: IPofServer1/32
          Destination: any (the Internet)
          NAT Address: publicIPofServer1

          Also remember to set up firewall rules on the DMZ network allowing access out. They only exist by default on LAN.

          Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.