Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    An interesting situation with NAT

    NAT
    1
    1
    368
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      chieftech
      last edited by

      Hi to all, Have some interesting experience. This topic about NAT with some prehistory

      2.4.2-RELEASE-p1 (amd64)
      built on Tue Dec 12 13:45:26 CST 2017
      FreeBSD 11.1-RELEASE-p6

      System have 3 WAN connections. Settings on the screenshots.

      Initially, my task was to find out how i can exclude the gateway from the rule "Gateway Swiching".

      In my case, was created interface for Openvpn connection, for flexible configuration of traffic and static routes.
      Of course this interface have own gateway which is displayed along with all.

      Once, for some reason the monitoring ip go offline, and Pfsense switched the defaul gateway to gateway of interface for VPN. This broke my entire routing. Besides, Pfsense does this even then Alarm latency on WANs.

      I create the topic with a question how i can exclude gateway frome rule "Gateway switching" - there I was advised to turn off this setting in System settings, which I did…

      Problems started when WAN that was set default goes down - NAT on another WANs was not working any more.
      In general, the problem sounds like this:
      In pfsense 2.4.2_p1 NAT does not work without default gateway.
      Besides, not working Squid and ddns ip cheking(Do not send an IP to ddns service), and packages check naturally too.

      I assumed that this problem is specific only on my system, but:
      In 2.3.3 release - does not work too.
      In 2.2.6 Release - all work fine, except for packages check but its naturally…

      In conclusion, I would very much like to:

      1. How to exclude the gateway I need, from the rule "gateway switching"? It would be nice to have such a parameter in the gateway settings.
      2. What's wrong with NAT?
      Sett.JPG
      Sett.JPG_thumb
      Sett2.JPG
      Sett2.JPG_thumb
      Sett3.JPG
      Sett3.JPG_thumb
      Sett4.JPG
      Sett4.JPG_thumb
      Sett5.JPG
      Sett5.JPG_thumb
      Sett6.JPG
      Sett6.JPG_thumb
      Sett7.JPG
      Sett7.JPG_thumb

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.