Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to do an inbound and outbound NAT at the same time ?

    Scheduled Pinned Locked Moved NAT
    nat
    5 Posts 2 Posters 860 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kujyh
      last edited by

      Hello

      Can pfsense perform a DNAT and a SNAT at the same time ?
      I am trying to replace an old firewall by a pfsense and theses few nat rules are annoying me.

      Here is an exemple of what i am trying to do :

      Before translation :
      Source‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ Destination‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ Port
      server1‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ FW_WAN_interface‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ 7474

      After translation :
      Source‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ Destination‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎Port
      FW_LAN_interface‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ computer1‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ 7474

      Thanks in advance for your help

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @kujyh
        last edited by

        @kujyh
        You will have to add two rules, a port forwarding and an outbound NAT rule to achieve this.

        K 1 Reply Last reply Reply Quote 1
        • K
          kujyh @viragomann
          last edited by

          @viragomann Does pfsense read the inbound rule before the outbond rule when the traffic come from the WAN to the LAN ?

          If so, do I have to adapt the second rule considering the traffic modified by the first rule ?

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @kujyh
            last edited by

            @kujyh
            Yes. But not clear if this really matters here.

            Add a NAT port forwarding rule on WAN, if needed specify the sourece as server1‏‏‎, dest is WAN address, dest port 7474 and redirect target is computer1 and port 7474.

            Then add an outbound NAT rule. You may have to switch to hybrid mode if it's still in automatic.
            Interface = LAN, source is again server1‏‏‎, destination computer1, dest. port 7474, translation address = "interface address".

            K 1 Reply Last reply Reply Quote 1
            • K
              kujyh @viragomann
              last edited by

              @viragomann i will try that, thanks :)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.