Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Outgoing NAT'ing from a single IP

    Scheduled Pinned Locked Moved NAT
    12 Posts 4 Posters 981 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • _neok_
      _neok
      last edited by _neok

      Hello, I have a problem whit Outbound NAT.
      I have an internet link with several public IP addresses. I need to make two computers go out to the internet inside my same LAN but by different public IP. I read in another post that I can use VIP and Manual/Hybrid Outbond NAT to do it. I've done it but I can't make it work.
      Any advice on how to make it work? Should I add a firewall rule?
      0_1547470970609_nat.PNG
      I leave a capture, from that IP I test and see that my public IP is sometimes the one I assign to NAT and sometimes not. I must do something else so that the public IP is always the one I assigned to it in Outbound NAT?
      By the way, I'm using Hybrid Outbound NAT.

      Thanks for help.
      Gabriel

      1 Reply Last reply Reply Quote 0
      • K
        kevinmitky
        last edited by

        You can use a firewall rule on your LAN side to specify a gateway for traffic matching the Source you specify. Look under Advanced->Gateway in the firewall rule.

        _neok_ 1 Reply Last reply Reply Quote 0
        • _neok_
          _neok @kevinmitky
          last edited by

          @kevinmitky And how would I do that? I have only one gateway. And I need to use a Virtual IP as the output IP so that the public IP is different.

          1 Reply Last reply Reply Quote 0
          • K
            kevinmitky
            last edited by

            If you have several public IPs I would assign them to gateways. Maybe I'm misunderstanding what your aim here is, I don't think you can use a virtual IP in public addressing space

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              Using hybrid outbound NAT with a VIP is the solution here. The rule shown should be OK, but keep in mind that it will only apply to new connections made after the rule was put in place. If the client had existing connections, those would still show in a packet capture as using the old address.

              You would have to clear the states or restart the client to ensure all of its connections are using the new rule.

              And checking the state table is much easier than using a packet capture.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              _neok_ 1 Reply Last reply Reply Quote 1
              • A
                ahmedkunnana
                last edited by

                dear
                i have the same issue , i tried this but its not working at all

                regards

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  @ahmedkunnana said in Outgoing NAT'ing from a single IP:

                  i have the same issue , i tried this but its not working at all

                  If you setup the VIP and rule properly, it works. Start your own thread with more information and specific details for assistance.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  A 1 Reply Last reply Reply Quote 1
                  • A
                    ahmedkunnana @jimp
                    last edited by

                    @jimp i already started mu owun subject
                    please help

                    regards

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      There is a whole forum full of people who can assist. I am not available for personalized help upon request.

                      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      A 1 Reply Last reply Reply Quote 1
                      • A
                        ahmedkunnana @jimp
                        last edited by

                        @jimp sorry sir

                        1 Reply Last reply Reply Quote 0
                        • _neok_
                          _neok @jimp
                          last edited by

                          @jimp thanks for reply.
                          I was able to make it work. There are some tricks to make it work well. Now I have to go. Tomorrow I write how I made it work.
                          Bye

                          Gabriel

                          _neok_ 1 Reply Last reply Reply Quote 0
                          • _neok_
                            _neok @_neok
                            last edited by _neok

                            @_neok said in Outgoing NAT'ing from a single IP:

                            @jimp thanks for reply.
                            I was able to make it work. There are some tricks to make it work well. Now I have to go. Tomorrow I write how I made it work.
                            Bye

                            Gabriel

                            I had a rule to allow me to navigate my entire LAN through another gateway. I had to make an IP alias of my LAN by taking out the local IP in question. Along with that I set the local IP to go out to the internet through the same gateway over which is the interface that has the VIP associated. That, in combination with the Hybrid Outbound NAT and that's it. I was able to fix it.

                            Thanks for help
                            Best regards

                            Gabriel

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.