<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[NAT Redirect Question]]></title><description><![CDATA[<p dir="auto">Hi all,</p>
<p dir="auto">I'm currently using some NAT rules to automatically redirect DNS queries to a Pi-hole DNS blocker / filter on my network in order to prevent clients from circumventing the Pi-hole by contacting another DNS server.  This is working fine, but I'm looking to make a minor adjustment:  Is there a way to adjust the NAT redirect rules or make an additional firewall rule to allow only one client on a subnet to talk to other DNS servers, but the rest of the clients on that subnet will still be forced to always go through the Pi-hole (i.e. will be bound by that DNS NAT Redirect rule)?  One way I see to do this is to put that one client on a separate subnet / VLAN, but I was hoping there might be another way as well.   Thanks in advance for your help, I really appreciate it.</p>
]]></description><link>https://forum.netgate.com/topic/144548/nat-redirect-question</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 19:22:31 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/144548.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 29 Jun 2019 18:47:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to NAT Redirect Question on Wed, 03 Jul 2019 13:00:47 GMT]]></title><description><![CDATA[<p dir="auto">Thanks <a class="plugin-mentions-user plugin-mentions-a" href="/user/nitrobeast">@<bdi>Nitrobeast</bdi></a> - really appreciate the help!</p>
]]></description><link>https://forum.netgate.com/post/851445</link><guid isPermaLink="true">https://forum.netgate.com/post/851445</guid><dc:creator><![CDATA[tman222]]></dc:creator><pubDate>Wed, 03 Jul 2019 13:00:47 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Redirect Question on Sun, 30 Jun 2019 00:47:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tman222">@<bdi>tman222</bdi></a> I went ahead and setup a pilot. Just create a brand new rule above the NAT firewall rule and add your alias to that rule. src = DNSBypassAlias dest = any.</p>
]]></description><link>https://forum.netgate.com/post/850958</link><guid isPermaLink="true">https://forum.netgate.com/post/850958</guid><dc:creator><![CDATA[Nitrobeast]]></dc:creator><pubDate>Sun, 30 Jun 2019 00:47:30 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Redirect Question on Sun, 30 Jun 2019 00:06:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tman222">@<bdi>tman222</bdi></a> Just add the pi-hole DNS to your bypass DNS alias so piehole can also bypass the NAT.</p>
]]></description><link>https://forum.netgate.com/post/850949</link><guid isPermaLink="true">https://forum.netgate.com/post/850949</guid><dc:creator><![CDATA[Nitrobeast]]></dc:creator><pubDate>Sun, 30 Jun 2019 00:06:08 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Redirect Question on Sat, 29 Jun 2019 19:26:38 GMT]]></title><description><![CDATA[<p dir="auto">Thanks <a class="plugin-mentions-user plugin-mentions-a" href="/user/nitrobeast">@<bdi>Nitrobeast</bdi></a> - this helps.  Just to clarify:</p>
<p dir="auto">Right now for the redirect rules I have source set to "Any" and for destination IP I'm using the Pi-hole IP with "invert match" checked.  Redirect target IP is set to be the IP of the Pi-hole.    The way I understand this in plain English it would be, "For any host on subnet if destination DNS request is not going to Pi-hole, redirect it to Pi-hole".</p>
<p dir="auto">Now, if I modify the rule to include a source alias as well like you described above, would the behavior essentially be this?</p>
<p dir="auto">'If source is not ByPassDNS host <strong>and</strong> destination for DNS request is not Pi-hole, redirect DNS request to Pi-hole."</p>
<p dir="auto">Does that sound right?  Thanks again for all your help.</p>
]]></description><link>https://forum.netgate.com/post/850934</link><guid isPermaLink="true">https://forum.netgate.com/post/850934</guid><dc:creator><![CDATA[tman222]]></dc:creator><pubDate>Sat, 29 Jun 2019 19:26:38 GMT</pubDate></item><item><title><![CDATA[Reply to NAT Redirect Question on Sat, 29 Jun 2019 19:05:45 GMT]]></title><description><![CDATA[<p dir="auto">The short answer is yes ... you can create an alias for your one device and in the NAT rule add the alias "if not alias then use NAT rule" see screenshot !!</p>
<p dir="auto"><img src="/assets/uploads/files/1561835138847-screenshot.1.jpg" alt="screenshot.1.jpg" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/850928</link><guid isPermaLink="true">https://forum.netgate.com/post/850928</guid><dc:creator><![CDATA[Nitrobeast]]></dc:creator><pubDate>Sat, 29 Jun 2019 19:05:45 GMT</pubDate></item></channel></rss>