Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple Public IP block

    Scheduled Pinned Locked Moved Routing and Multi WAN
    8 Posts 3 Posters 539 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      EngineerSB
      last edited by

      We have a /29 block assignment from our ISP presently we have an agening cisco ASA. Its second powersupply in two years has died so its time to replace the device and I'm looking at netgate as a possible alternative.

      Some of these addresses are transparently passed through to internal devices so it appears the raw connection is directly connected to the server which inturns means its comminucation comes from its own public IP and some of the other public IPs are NAT'd to internal networks, eg. staff/accounts/admin/guest etc.

      I've not been able to find a conclusive description of how to go about this via pfsense. any pointers to documention or other info would be greatly received.

      1 Reply Last reply Reply Quote 0
      • pttP
        ptt Rebel Alliance
        last edited by

        https://docs.netgate.com/pfsense/en/latest/search.html?q=public&check_keywords=yes&area=default

        E 1 Reply Last reply Reply Quote 0
        • kiokomanK
          kiokoman LAYER 8
          last edited by

          https://docs.netgate.com/pfsense/en/latest/firewall/virtual-ip-addresses.html
          https://www.youtube.com/watch?v=JGZvJOiZ5Tg

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          E 1 Reply Last reply Reply Quote 0
          • E
            EngineerSB @ptt
            last edited by

            @ptt thank you for the link, could you offer some explaination please and a little guidence.

            In practice and the real world how does this work?

            1 Reply Last reply Reply Quote 0
            • E
              EngineerSB @kiokoman
              last edited by

              @kiokoman Thank you for the video link. Very informative. Just what I was looking for.

              How do we go about making internal traffic from one of our servers orgininate from the public IP it is assigned?

              eg.
              server 1 - public 1
              server 2 - public 2
              server 3 - public 3 etc.

              I've not understood how to ensure server 3 when it connects to external services it appears to come from its public 3 IP addresss? - hope this makes sense.

              1 Reply Last reply Reply Quote 0
              • kiokomanK
                kiokoman LAYER 8
                last edited by

                uhm yes, the video does not show that part anyway it's really easy,
                you just need an outbound rule, like this

                Immagine.jpg

                ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                Please do not use chat/PM to ask for help
                we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                1 Reply Last reply Reply Quote 0
                • E
                  EngineerSB
                  last edited by

                  I see, so the source can be the entire net or I guess the specific IP of the internal server?

                  1 Reply Last reply Reply Quote 0
                  • kiokomanK
                    kiokoman LAYER 8
                    last edited by

                    yes, I have only one server inside that network so I didn't care to set a /32 but you can do that

                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                    Please do not use chat/PM to ask for help
                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.