Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Double NAT problem

    NAT
    5
    17
    6190
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      balubeto last edited by

      Hi

      I have a firewall hardware (192.168.1.1) with pfSense 2.3.2 64 bit which manages a LAN (192.168.1.0) with 8 network devices with fixed IPs.

      On the WAN port of the firewall, I connected a VDSL2 router (10.0.0.1) that manages the Internet connection and provides Internet to the LAN.

      To get Internet on the LAN, unfortunately, I have to enable the router's NAT.

      So now, my LAN sees both the firewall NAT is that of the VDSL2 router causing some problems on the LAN.

      So how should I configure pfSense to make sure that the LAN only see the firewall's NAT?

      The firewall and router configuration is:





      Thanks

      Bye

      balubeto

      1 Reply Last reply Reply Quote 0
      • B
        balubeto last edited by

        In other words, how I should configure pfSense to ensure that the two NAT do not interfere with each other?

        Thanks

        Bye

        balubeto

        1 Reply Last reply Reply Quote 0
        • V
          viragomann last edited by

          Just ensure that both routers do NAT in both direction. On the VDSL router this should be set by default.
          On pfSense this is default as well, you may check it in Firewall > NAT > Outbound. It should be set to automatic rule generation.

          Also ensure that "Block private networks and loopback addresses" is unchecked in the WAN interface settings, since you have a private WAN subnet.

          1 Reply Last reply Reply Quote 0
          • B
            balubeto last edited by

            @viragomann:

            Just ensure that both routers do NAT in both direction. On the VDSL router this should be set by default.
            On pfSense this is default as well, you may check it in Firewall > NAT > Outbound. It should be set to automatic rule generation.

            Also ensure that "Block private networks and loopback addresses" is unchecked in the WAN interface settings, since you have a private WAN subnet.

            These settings

            are right?

            Thanks

            Bye

            balubeto

            1 Reply Last reply Reply Quote 0
            • V
              viragomann last edited by

              Yeah, it should work properly with this setting.

              What's the problem?
              The crucial sentence in your first post
              @balubeto:

              So now, my LAN sees both the firewall NAT is that of the VDSL2 router causing some problems on the LAN.

              isn't understandable.

              1 Reply Last reply Reply Quote 0
              • B
                balubeto last edited by

                @viragomann:

                Yeah, it should work properly with this setting.

                What's the problem?
                The crucial sentence in your first post
                @balubeto:

                So now, my LAN sees both the firewall NAT is that of the VDSL2 router causing some problems on the LAN.

                isn't understandable.

                My computers with Windows 7 SP1 on the LAN see two NAT.

                Whereas if I unplug the VDSL2 router from the firewall, the computers see an only NAT and, therefore, the LAN is working properly.

                So how do I fix this?

                Thanks

                Bye

                balubeto

                1 Reply Last reply Reply Quote 0
                • JKnott
                  JKnott last edited by

                  How is your equipment connected?  I can't imagine any scenario in which a computer could see both, unless somehow connected to both.  Normally, when you have double NAT, you see only the one you're connected to.

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  1 Reply Last reply Reply Quote 0
                  • B
                    balubeto last edited by

                    @JKnott:

                    How is your equipment connected?  I can't imagine any scenario in which a computer could see both, unless somehow connected to both.  Normally, when you have double NAT, you see only the one you're connected to.

                    My LAN is composed of a hardware firewall, a NAS, a network printer, two smart TV and 6 computers with Windows 7 SP1. Also, I have a VDSL2 router, connected to the WAN port on the firewall, which provides Internet to the LAN.

                    All of these network devices have fixed IPs and have the DHCP disabled.

                    So why computers even see the router's NAT?

                    Thanks

                    Bye

                    balubeto

                    1 Reply Last reply Reply Quote 0
                    • B
                      balubeto last edited by

                      I tried a new configuration of the firewall but the devices connected to the 192.168.1.0 network can still see the 10.0.0.0 network NAT causing malfunctions to the main network.

                      If I disable the NAT of the 10.0.0.0 network, the first network returns to work properly but I have no more Internet on this network.

                      So how should I do to make sure that the main network does not see the secondary network NAT?

                      The new firewall (192.168.1.1) and VDSL2 router (10.0.0.1) configuration  is:











                      Thanks

                      Bye

                      balubeto

                      1 Reply Last reply Reply Quote 0
                      • ptt
                        ptt Rebel Alliance last edited by

                        ???  LAN: 192.168.1.1 with "GW_LAN: 192.168.1.1"  ?

                        https://doc.pfsense.org/index.php/Connectivity_Troubleshooting#LAN_Interface

                        1 Reply Last reply Reply Quote 0
                        • B
                          balubeto last edited by

                          @ptt:

                          ???  LAN: 192.168.1.1 with "GW_LAN: 192.168.1.1"  ?

                          https://doc.pfsense.org/index.php/Connectivity_Troubleshooting#LAN_Interface

                          So, what should I change?

                          Thanks

                          Bye

                          balubeto

                          1 Reply Last reply Reply Quote 0
                          • B
                            balubeto last edited by

                            @balubeto:

                            @ptt:

                            ???  LAN: 192.168.1.1 with "GW_LAN: 192.168.1.1"  ?

                            https://doc.pfsense.org/index.php/Connectivity_Troubleshooting#LAN_Interface

                            So, what should I change?

                            Thanks

                            Bye

                            If I set the LAN interface to 192.168.1.254, the Internet does not work anymore. Why?

                            Thanks

                            Bye

                            balubeto

                            1 Reply Last reply Reply Quote 0
                            • V
                              viragomann last edited by

                              You should not set any gateway on LAN interface if the pfSense is the LAN gateway.

                              1 Reply Last reply Reply Quote 0
                              • B
                                balubeto last edited by

                                I also tried to change the LAN gateway, but it is always offline.




                                Where am I wrong?

                                Thanks

                                Bye

                                balubeto

                                1 Reply Last reply Reply Quote 0
                                • H
                                  hda last edited by

                                  @balubeto:

                                  Where am I wrong?

                                  Besides Trial & Horror, read #12 again. Remove that gateway for the LAN…

                                  1 Reply Last reply Reply Quote 0
                                  • B
                                    balubeto last edited by

                                    @hda:

                                    @balubeto:

                                    Where am I wrong?

                                    Besides Trial & Horror, read #12 again. Remove that gateway for the LAN…

                                    I deleted the gateway that was always offline.The router's NAT causes some malfunctions and slowdowns in the LAN.

                                    If, though, off the NAT the LAN returns to work, but the Internet does not work on the LAN.If I put the router in Bridge mode (disabling its NAT and disconnecting the Internet connection) I should enable the PPPoE client on the firewall to manage the Internet on the LAN.

                                    In this case, but, the analog phone and fax machine connected to the router will not work.

                                    So how do I solve this problem of the phone and fax?

                                    Thanks

                                    Bye

                                    balubeto

                                    1 Reply Last reply Reply Quote 0
                                    • B
                                      balubeto last edited by

                                      If I had to do in this way:




                                      I would still have the Internet service on the LAN?

                                      Thanks

                                      Bye

                                      balubeto

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post