Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Kind of complex question regarding routing multiple public ips to multiple lans

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 847 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      elementalwindx
      last edited by

      Ok I have a pfsense setup as such:

      Connected to 1 cable WAN interface with a pool of 5 static IPs. I have 2 seperate lans on my network (Lan A: 192.168.1.0/24, Lan B VLAN6: 192.168.2.0/24)

      Currently both LAN's go out the same public IP.

      How can I get the 2nd LAN to go out the 2nd public IP address? I have another available nic port on both the cable modem and the pfsense unit if that leaves one option open.

      Thanks.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Well you create a VIP on your wan interface of pfsense for one of your other pubic IPs you have.  Then create an outbound nat rule that says all clients on Lan B use the VIP as their nat vs the actual wan interface IP.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • E
          elementalwindx
          last edited by

          @johnpoz:

          Well you create a VIP on your wan interface of pfsense for one of your other pubic IPs you have.  Then create an outbound nat rule that says all clients on Lan B use the VIP as their nat vs the actual wan interface IP.

          Awesome. Thanks :) Got it to work. Had to set the rule generation to manual, and modify a couple rules that were in there for some unknown reason. I think it had to do with an old public IP we use to have.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            well yeah your automatic rules would of been natting that source network for you.  You might have been able to just use hybrid since I believe the hybrid rules are evaluated first.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.