<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[LAN to WAN Internet Traffic Setup]]></title><description><![CDATA[<p dir="auto">I am attempting to set up a PFSense Firewall to sit between my private network and the world in AWS and act as a firewall/forward proxy. I set the box up with 2 interfaces, WAN (on 10.8.162.6 with a gateway of 10.8.160.1 on a /20 network) and LAN (on 10.8.96.6 on a /20 network, set none on the upstream gateway). Initially, I set up the box without the squid proxy just to make sure I had connectivity between the LAN and WAN. I forwarded the traffic to the LAN but it would not talk to the WAN interface.</p>
<p dir="auto">The next stuff I did, made the traffic be able to talk to the internet and go back to the box, but I know it is not the correct way to do it.</p>
<p dir="auto">-Created the WAN gateway 10.8.160.1<br />
-Created the LAN gateway 10.8.96.1<br />
-Created firewall rules to allow any traffic to the LAN interface.<br />
-Created firewall rule to allow traffic from LAN to WAN<br />
-Created NAT to nat traffic coming from 10.0.0.0/8 to the WAN interface.<br />
-Set the Pure NAT option in the advanced settings.<br />
-Set the reflection option in the NAT settings.</p>
<p dir="auto">(this is eventually what made the traffic flow, but is wrong)<br />
-Set route for 0.0.0.0/1 to the Wan Interface<br />
-Set route for 128.0.0.0/1 to the Wan interface<br />
-Set route for 10.8.96.0/20 to the LAN interface<br />
-Set route for 10.8.128.0/20 to the LAN interface (IP address space of the computer I'm testing with)</p>
<p dir="auto">The AWS space has a CIDR of 10.8.0.0/16 so all but the DMZ subnet (10.160.0.0/20) will point to PFSense for connectivity to the Outside.</p>
<p dir="auto">My question: What is the correct way to set my box up for what I am trying to accomplish? The default setup is not working for me and I don't know what it is I need to add. I'm also wondering why the stuff coming in to the LAN interface isn't picking up on the default route in PFSense. The biggest thing I have a problem with is that pseudo default route I put in.</p>
<p dir="auto">Any help is appreciated</p>
]]></description><link>https://forum.netgate.com/topic/143554/lan-to-wan-internet-traffic-setup</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 08:44:00 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/143554.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 21 May 2019 15:40:04 GMT</pubDate><ttl>60</ttl></channel></rss>