<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[1:1 NAT across IPsec tunnel?]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">I saw this was not supported in the past (3+ years ago) and wanted to see if this is possible in the latest version or if anyone else has been able to get this to work?</p>
<p dir="auto">I've done 1:1 host NAT entries before with ASAs and would like to do the same with pfSense.  I understand BiNAT works under the phase 2 settings for the entire network but I'd like to NAT multiple 1:1 entries.  Setting up at outbound NAT or 1:1 NAT shows the internal IP undergoing NAT but it never traverses the IPsec tunnel.</p>
<p dir="auto">Still a no-go with pfSense?</p>
<p dir="auto">Thanks for your time!</p>
]]></description><link>https://forum.netgate.com/topic/144094/1-1-nat-across-ipsec-tunnel</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 20:24:20 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/144094.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 12 Jun 2019 14:10:15 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 1:1 NAT across IPsec tunnel? on Thu, 13 Jun 2019 14:44:03 GMT]]></title><description><![CDATA[<p dir="auto">You have to use Phase 2 entries with BINAT. You can make one phase 2 entry per mapping if you must do them individually.</p>
]]></description><link>https://forum.netgate.com/post/848162</link><guid isPermaLink="true">https://forum.netgate.com/post/848162</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Thu, 13 Jun 2019 14:44:03 GMT</pubDate></item></channel></rss>