Using /29 - virtual ip's or wan vlan?
-
I've done nat fwd rules, and I've used a wan vlan to spit a /29 between 3 different vendor routers - but I've never set it up in pf using virtual ip's.
(well, once using non routable internal for a ha mockup)
Is there any particular advantage using vip's - particularly over vlanning it?
The use case I have in mind at the moment is exposing dns and/or a proxy for road warriors.
-
You really cannot make an inside interface wwith public addresses with a single /29 on WAN. The best you can do is 1:1 NAT addresses to inside hosts. Some people bridge WAN so they can put hosts on public IP addresses. Not a fan.
If they were to route another subnet to an address on that /29 you could use that subnet on an inside interface, use VIPs on WAN, or basically do whatever you want.