• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

need to change ip address after openvpn

Scheduled Pinned Locked Moved NAT
9 Posts 2 Posters 583 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • W
    wilfrid
    last edited by Feb 1, 2021, 3:27 PM

    Hi guys,

    I have a pfSense with an openVPN server for routing to a external subnet.
    The transfer net is 192.168.88.0 , the external network is 192.168.49.0 and my lan behind the pfSense is 192.168.0.0

    Now a client from the second network (ex. 192.168.49.101) will make a envoking to 192.168.0.25;
    this client (the 192.168.0.25) allowed only client from the local addresses.
    How can I transfer my external address 192.168.49.101 to 192.168.0.101 ??

    I have try to make a NAT 1:1, but there was no result ...

    any ideas ?

    thank you

    V 1 Reply Last reply Feb 1, 2021, 4:06 PM Reply Quote 0
    • V
      viragomann @wilfrid
      last edited by Feb 1, 2021, 4:06 PM

      @wilfrid
      You can do this with outbound NAT on pfSense.

      Switch to the hybrid operation mode first and save it.
      Then add a new rule:
      interface: LAN
      source: the external network
      dest: 192.168.0.25
      translation: interface address

      W 1 Reply Last reply Feb 1, 2021, 4:35 PM Reply Quote 0
      • W
        wilfrid @viragomann
        last edited by Feb 1, 2021, 4:35 PM

        @viragomann : Its dont work so, I dont need all traffic to the new address.

        I need that the client from second network ex 192.168.49.101 has for all traffic in first network the client address 192.168.0.101,
        like a local client ....

        V 1 Reply Last reply Feb 1, 2021, 4:58 PM Reply Quote 0
        • V
          viragomann @wilfrid
          last edited by Feb 1, 2021, 4:58 PM

          @wilfrid said in need to change ip address after openvpn:

          Its dont work so, I dont need all traffic to the new address.

          This does not apply to the whole traffic, it only applies to what you enter at source and destination.

          I need that the client from second network ex 192.168.49.101 has for all traffic in first network the client address 192.168.0.101,
          like a local client ....

          What is the different between interface address and any other IP in the local range for this purpose?

          If you want to access the server using 192.168.0.101 for whatever reason, add this IP to the LAN interface as "IP Alias" and then select it in the outbound NAT rule at translation address.

          W 1 Reply Last reply Feb 1, 2021, 5:29 PM Reply Quote 0
          • W
            wilfrid @viragomann
            last edited by Feb 1, 2021, 5:29 PM

            @viragomann : the reason for this NAT is there is a client that only allows access from this network.
            I have a site to site connected VPN over a tunnel network and need now that the second client get a (virtual) address from local network

            LAN2 192.168.490 /24

            PC1 192.168.49.101 <=== VPN ===>

            W 1 Reply Last reply Feb 1, 2021, 5:32 PM Reply Quote 0
            • W
              wilfrid @wilfrid
              last edited by Feb 1, 2021, 5:32 PM

              @wilfrid

              LAN 2 192.168.49.0 / 24 Tunnel 192.168.99.0/30 LAN 1 192.168.0.0 /24

              PC1 192.168.49.101 <======VPN ======> access to 192.168.0.25 as local client
              (the client address must be in 192.168.0.0/24)

              V 1 Reply Last reply Feb 1, 2021, 5:35 PM Reply Quote 0
              • V
                viragomann @wilfrid
                last edited by Feb 1, 2021, 5:35 PM

                @wilfrid
                So add the outbound NAT rule as suggested above and it is done well.

                W 1 Reply Last reply Feb 1, 2021, 5:42 PM Reply Quote 0
                • W
                  wilfrid @viragomann
                  last edited by Feb 1, 2021, 5:42 PM

                  @viragomann
                  I have do this,
                  but if I capture packets with the diagnostic tool is there only the original network address

                  W 1 Reply Last reply Feb 1, 2021, 5:45 PM Reply Quote 0
                  • W
                    wilfrid @wilfrid
                    last edited by Feb 1, 2021, 5:45 PM

                    @wilfrid thank you , its work

                    1 Reply Last reply Reply Quote 0
                    1 out of 9
                    • First post
                      1/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received