Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Do i need to to Turn Off NAT on my Mikrotik router,while Pfsense hanfout Leases

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 4 Posters 809 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      OpenWifi
      last edited by

      Hello Guys, i would like your suggestions. So i have a Mikrotik router and a pfsense router. My plan is to setup the Mikrotik as the Loadbalancer and pfsense SG-2440 as the router handing out leases to Clients. So my question is ; Do i need to turn off NAT on Mikrotik ?

      NollipfSenseN 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        What sort of NAT? Outbound?

        What sort of load-balancing is it doing? The NAT may be required there for it to work.

        It's generally better to have public IPs on the pfSense WAN(s) but I have no idea if Mikrotik can pass those and still load-balance.

        That's assuming the Microtik will be on the pfSense WAN side.

        Steve

        1 Reply Last reply Reply Quote 0
        • NollipfSenseN
          NollipfSense @OpenWifi
          last edited by

          @OpenWifi I also used a pfSense/Mikrotik combination in my network; however, I let the pfSense be in charge of WAN and the Mikrotik in charge of LAN ... so, the Mikrotik issues client leases as well as DNS cache with pfBlockerNG on pfSense as the ultimate DNS resolver. It's double natted, but I have never experienced any problem ... so, I let it be.

          If I were you, I would let pfSense do the load balancing as well as IDS/IPS. I really like both pfSense and Mikrotik despite my network training started with Mikrotik.

          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

          O 1 Reply Last reply Reply Quote 0
          • O
            OpenWifi @NollipfSense
            last edited by

            @NollipfSense Hello, thank you for the suggestion, but you see the reason i would like to use Mikrotik as the loadbalancer and pfsense as the lease handler is because pfsense has so many great features that Mikrotik doesn't. For example; Ntopng lets me see what traffic is going through my network. OpenVpn lets me login remotely to the pfsense router, which i fear to loose that capability when i use Mikrotik as the lease handler.Another great feature, is that i am able to prevent any unauthorized dhcp clients using static ips and this happens automatically. I dont have to go to each and every of my client to set the static lease, the way Mikrotik does.

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @OpenWifi
              last edited by

              @OpenWifi said in Do i need to to Turn Off NAT on my Mikrotik router,while Pfsense hanfout Leases:

              I dont have to go to each and every of my client to set the static lease

              To set up a static DHCP lease you need the MAC of the client device.
              Just look at the DHCP server log, locate the MAC, and create a DHCP Static lease entry.
              Next time the lease is renewed, the assigned IP will get used.

              No need to "go to the device".

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              NollipfSenseN 1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                More detail required. What and how are you load balancing?

                1 Reply Last reply Reply Quote 0
                • NollipfSenseN
                  NollipfSense @Gertjan
                  last edited by

                  @OpenWifi said in Do i need to to Turn Off NAT on my Mikrotik router,while Pfsense hanfout Leases:

                  pfsense has so many great features that Mikrotik doesn't

                  That's why I prefer pfSense at the edge.

                  @OpenWifi said in Do i need to to Turn Off NAT on my Mikrotik router,while Pfsense hanfout Leases:

                  Ntopng lets me see what traffic is going through my network

                  For this you would need to disable NAT on the Mikrotik else all traffic would be coming from 192.168.1.100

                  @OpenWifi said in Do i need to to Turn Off NAT on my Mikrotik router,while Pfsense hanfout Leases:

                  I dont have to go to each and every of my client to set the static lease, the way Mikrotik does.

                  In Mikrotik, go to IP > DHCP Server > Lease ... if you click on the lease you'll see an interface tab like below ... notice one arrow points to "D" dynamic lease that you can "make static."

                  Screen Shot 2020-07-24 at 10.26.59 PM.png

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.