Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    I think I'm having a problem with outbound Nat

    NAT
    2
    4
    403
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cwesterfield last edited by

      I'm attempting to get two subnets to route differently. I'd like my LAN to go out via ISP, and a Guest subnet out through PIA.

      I have my outbound NAT rules built, but only the guest subnet can route out to the internet.

      I'm not sure why the WAN rule wont allow me to get out.

      I've attached the PC tests and my rules.



      1 Reply Last reply Reply Quote 0
      • Derelict
        Derelict LAYER 8 Netgate last edited by

        Outbound NAT doesn't route traffic. Routing and Policy routing does.

        What routing and policy routing do you have configured for the various interfaces?

        Chattanooga, Tennessee, USA
        The pfSense Book is free of charge!
        DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • C
          cwesterfield last edited by

          Lan and Guest Rules attached.

          The Lan rule currently has a Gateway (WAN_DHCP) designated, because it gives parts of my lan internet but breaks inter-connectivity to my bridge interfaces. My Lan is 3 bridged devices, and the three devices get isolated when i have WAN_DHCP gateway designated.

          The Guest subnet doesn't have a gateway rule and somehow still routes over the PIA gateway. This is very confusing to me.

          How does the outbound NAT function as I currently have it? Why does the guest subnet work the way I want it to without a policy based gateway rule?






          1 Reply Last reply Reply Quote 0
          • Derelict
            Derelict LAYER 8 Netgate last edited by

            You have to bypass policy routing for internal network prior to the policy routing rule that matches.

            https://doc.pfsense.org/index.php/Bypassing_Policy_Routing

            Chattanooga, Tennessee, USA
            The pfSense Book is free of charge!
            DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post