• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Outbound NAT rule generation & FRR OSPF-learned routes/subnets

Scheduled Pinned Locked Moved FRR
2 Posts 2 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • V
    Varashi
    last edited by Dec 15, 2017, 1:06 PM

    In playing with FRR OSPF I have stumbled accross an issue with Outbound NAT.

    It seems that only connected and statically-defined kernel routes are automatically added to the Outbound NAT rule, however OSPF-learned subnets are not.

    Took me quite some time to figure out why my VMs in remote subnets had access to everything, could perfectly be accessed from the internet, but could not establish any connection towards the internet themselves :D

    In the end I just added an "any" Outbound NAT rule to re-establish internet access for those VMs, but this seems like a bad practice.

    One of the reasons I'm using OSPF (apart from learning) is to not have to bother too much with various reconfigs all over the place to make a new subnet work. (I'm experimenting with VMware NSX and automation).
    Thus my question is… is there a way to let OSPF-learned subnets be added to the Outbound NAT rules automatically, or does this functionality not exist?
    If not, would a feature request for this be something to consider?

    Thanks!

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Dec 15, 2017, 1:23 PM

      No. There is no way that dynamic routes can be picked up by automatic outbound NAT.

      If they are all privately numbered, you could make an RFC1918 alias (192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8) and then setup hybrid or manual outbound NAT rules to match that alias as a source.

      Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received