Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to do use this NAT?

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    36 Posts 3 Posters 3.8k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD Offline
      Derelict LAYER 8 Netgate
      last edited by

      Monitor pings every half-second by default. This is an ICMP echo request looking for an echo reply. Not sure what you're asking.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • A Offline
        akong77
        last edited by

        My Wan is set private ip use 192.168.15.2/24 and set gateway is 61.220.69.254. This gateway ip is true. And I can ping to anywhere. But monitor always show offline.

        1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by

          Then pings to the monitor IP address are not being returned.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            akong77 @Derelict
            last edited by

            @Derelict So if I use private ip at WAN interface. The monitor is show offline is normal?

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              Yes. That is why you need three routable IP addresses to do HA correctly. Else only the node that holds the CARP address can access the internet.

              If it is worth HA it is worth doing correctly.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • A Offline
                akong77
                last edited by

                Hello, I have two wan interface. I has set private ip on two wan interface. It's can ping outgoing on pfsense. I has set default gateway. But client pc only go default gateway to internet. If client pc set outbound NAT to none default gateway. It's can't go to internet. How to set up it?

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  No idea based on that description. Sorry. Please post more details.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    akong77
                    last edited by

                    Sorry.
                    WAN1 -- 192.168.15.2/24 and gateway set to 1.2.3.254
                    WAN1 have five CARP IPs.
                    WAN2 -- 192.168.20.2/24 and gateway set to 5.6.7.254
                    WAN2 have file CARP IPs.
                    LAN1 -- 192.168.0.0/24
                    LAN2 -- 192.168.10.0/24
                    Outbound NAT set LAN1 to WAN2 CARP IP. Set LAN2 to WAN1 CARP IP.
                    I set default gateway as WAN2.
                    It's only LAN1 user can go to internet. LAN2 user can't go to internet.
                    If I set default gateway is WAN1.
                    It's only LAN2 user can go to internet. LAN1 user can't.
                    How to set it?

                    1 Reply Last reply Reply Quote 0
                    • DerelictD Offline
                      Derelict LAYER 8 Netgate
                      last edited by

                      You do not route traffic with Outbound NAT rules. You route traffic with policy routing rules.

                      Set your Outbound NAT for all inside source addresses on both WANs to the proper CARP VIP.

                      Policy routing determines what traffic flows out which interface.

                      https://docs.netgate.com/pfsense/en/latest/book/multiwan/policy-routing-configuration.html#policy-routing-configuration

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • A Offline
                        akong77
                        last edited by

                        So in addition to setting the Outbound NAT to the CARP IP, also set the Gateway in LAN1 and LAN2's Rules, right?

                        1 Reply Last reply Reply Quote 0
                        • A Offline
                          akong77
                          last edited by

                          Hello,
                          I has set finish all WAN and LAN setting and success it. But I have another problem. I set openvpn on it and click on redirect ipv4 gateway this option. But when client connect openvpn server. It's can't go to internet. If I click off redirect ipv4 gateway. It's can go to internet. But it's use original IP. I has set firewall rules all allow for OPENVPN tab. Could any loss another setting?

                          1 Reply Last reply Reply Quote 0
                          • DerelictD Offline
                            Derelict LAYER 8 Netgate
                            last edited by

                            Outbound NAT for the tunnel network source addresses. Again, the NAT address should be the CARP VIP just like for any other inside network.

                            You also need to pass all traffic on the OpenVPN firewall rules.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • A Offline
                              akong77
                              last edited by

                              Thanks a lot. I have another question. I has set some NAT setting.
                              NAT Reflection mode --> PureNAT
                              Enable NAT Reflection for 1:1 NAT --> check on.
                              Enable automatic outbound NAT for Reflection --> check on.
                              But user can't browser intranet web page when this web page resolve IP is CARP IP.Could I miss another setting?

                              1 Reply Last reply Reply Quote 0
                              • DerelictD Offline
                                Derelict LAYER 8 Netgate
                                last edited by

                                Doesn't sound like it. Split DNS is generally considered a more effective solution.

                                But it depends. You'll have to post everything including the firewall rules for the interface the users are sourcing from.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • A Offline
                                  akong77
                                  last edited by

                                  I got some pic about firewall rules.
                                  Please see attachment.
                                  WAN1.PNG WAN2.PNG LAN1.PNG LAN2.PNG
                                  I have not set any block rules. Could have any problem?

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD Offline
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    What, specifically, is not working?

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.