<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Multiple exceptions for outgoing NAT]]></title><description><![CDATA[<p dir="auto">Hello everybody,</p>
<p dir="auto">I would like to exclude multiple IP subnets from my outgoing NAT rules but I<br />
don't know how.</p>
<p dir="auto">I understand that it is not directly possible, as shown in the picture<br />
outgoingNAT.png. But is there a way to exclude multiple networks from NAT?<br />
I thought to configure multiple rules, each with an IP network as an<br />
exception. However, this cannot work because the first rule would match for<br />
IP networks that are excluded in the following rules:<br />
1. NAT for everything except 192.168.0.0/16<br />
2. NAT for everything except 172.12.0.0/12<br />
3. NAT for everything except 10.0.0.0.0/8</p>
<p dir="auto">A packet from 10.0.0.1 would match in the first rule. But it should actually<br />
be excluded from the NAT process.</p>
<p dir="auto">Does anyone have an idea how to solve this problem?</p>
<p dir="auto">Cheers,<br />
Helge</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/outgoingNAT.PNG" alt="outgoingNAT.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/outgoingNAT.PNG_thumb" alt="outgoingNAT.PNG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/129649/multiple-exceptions-for-outgoing-nat</link><generator>RSS for Node</generator><lastBuildDate>Sat, 15 Aug 2026 07:48:00 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/129649.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 13 Apr 2018 06:55:00 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Multiple exceptions for outgoing NAT on Fri, 13 Apr 2018 11:06:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a>:</p>
<blockquote>
<p dir="auto">Just put all your the subnets into an alias (Firewall &gt; Aliases).<br />
Add an outbound NAT rule for the corresponding interface, check "Do not NAT", at destination select Network and enter the alias name.<br />
Put this NAT rule to the top of the rule set. Now outbound NAT is disabled for the subnets contained in the alias.</p>
</blockquote>
<p dir="auto">That's the trick… Thank you very much. Works great.</p>
]]></description><link>https://forum.netgate.com/post/760746</link><guid isPermaLink="true">https://forum.netgate.com/post/760746</guid><dc:creator><![CDATA[der.helge]]></dc:creator><pubDate>Fri, 13 Apr 2018 11:06:49 GMT</pubDate></item><item><title><![CDATA[Reply to Multiple exceptions for outgoing NAT on Fri, 13 Apr 2018 10:54:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/der.helge">@<bdi>der.helge</bdi></a>:</p>
<blockquote>
<p dir="auto">I would like to exclude multiple IP subnets from my outgoing NAT rules but I<br />
don't know how.</p>
</blockquote>
<p dir="auto">Destination subnet, as your screenshot shows?</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/der.helge">@<bdi>der.helge</bdi></a>:</p>
<blockquote>
<p dir="auto">I understand that it is not directly possible, as shown in the picture<br />
outgoingNAT.png. But is there a way to exclude multiple networks from NAT?</p>
</blockquote>
<p dir="auto">Just put all your the subnets into an alias (Firewall &gt; Aliases).<br />
Add an outbound NAT rule for the corresponding interface, check "Do not NAT", at destination select Network and enter the alias name.<br />
Put this NAT rule to the top of the rule set. Now outbound NAT is disabled for the subnets contained in the alias.</p>
]]></description><link>https://forum.netgate.com/post/760739</link><guid isPermaLink="true">https://forum.netgate.com/post/760739</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 13 Apr 2018 10:54:02 GMT</pubDate></item></channel></rss>