Do I need to specify a dest add in rules & nat?

  • I have a pfsense box working well.
    When creating rules I like to create the NAT separately.
    When creating both rules & NAT I can specify the destination address however I am unsure if I just need to specify for rules, NAT or both?
    If my rules have the dest address locked down is there any advantage in also specifying the dest address in NAT?

  • LAYER 8 Netgate

    NAT happens before firewall rules are applied so if you are port forwarding, say, WAN address:80 to you need to pass traffic to on WAN.

    The automatically-generated rules on a port forward will always do the right thing.

Log in to reply