Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Question about reflection

    Scheduled Pinned Locked Moved NAT
    1 Posts 1 Posters 392 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      laeuchli
      last edited by

      All,
      I have the following pfsense setup. My WAN is 192.168.1.x and my LAN is 172.16.0.x.

      I am using NAT to translate RDP requests. I have an internet facing IP(not under my control), that is forwarded to my pfsense IP at 192.168.1.10. Based on this port I then get forwarded to the correct 172.16.0.X address, and go about my RDP business. This works correctly.

      My problem is I have another machine on address 192.168.1.180 that I would like to RDP from my external IP address(Recall this is forwarded directly to my pfsense). I add a NAT rule to map to this IP address, but of course it is not a LAN address, so it does not work. When I enable NAT reflection and attempt the connection from inside my network the request to the external address gets kicked to my 192.168.1.X gateway, and then on to my 192.168.1.10 address and then it works. However when I connect from outside my network nothing happens(Tcpdump just shows a connection between this external address and 192.168.1.10 and then nothing else).

      The reflection settings says that "Required for full functionality of the pure NAT mode of NAT Reflection for port forwards or NAT Reflection for 1:1 NAT. Note: This only works for assigned interfaces. Other interfaces require manually creating the outbound NAT rules that direct the reply packets back through the router." so I Guess I need to create some sort of outbound NAT rule, but I'm not really sure what this rule should look like or if this is exactly the right approach.

      Any help greatly appreciated.
      Pericles

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.