Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Nested aliases of Host(s) and Network(s) types. Is it correct?

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 469 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      dezore
      last edited by dezore

      Hi there!
      I've searched through the forum and failed to find a direct answer.

      I have a few aliases:
      Alias A, type Host(s), which contains IP addresses. (X.X.X.X)
      Alias B, type Network(s), which contains networks. (X.X.X.X/YY)

      I've created Alias C, type Host(s), which contains Alias A and Alias B.
      There was no error from the pfSense side, and it was allowed.
      I used this alias for NAT rules + associated Firewall rules, and it seems to be working.

      How legit is this operation? Can I use such kind of mixing without any issues?

      Thanks in advance.
      pfSense+ 21.05.1

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        You should be able to create mixed nested aliases like that. However I would recommend avoiding them if you can. There have been issues in the past populating those if something fails to resolve and indeed there are still open bugs for specific situations.

        Check Diag > Tables to see exactly what the resulting alias table has been populated with.

        Steve

        bingo600B D 2 Replies Last reply Reply Quote 0
        • bingo600B Offline
          bingo600 @stephenw10
          last edited by

          @stephenw10
          If one was to use hosts in Alias B as a /32 network definition , could that be ok ?
          I mean mixing Alias A & Alias B , in Alias C

          I mean then it is "all network aliases" ...
          You'll prob. loose the "dns resolve" feature from the host alias.

          But else ....

          /Bingo

          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

          pfSense+ 23.05.1 (ZFS)

          QOTOM-Q355G4 Quad Lan.
          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

          1 Reply Last reply Reply Quote 0
          • D Offline
            dezore @stephenw10
            last edited by

            @stephenw10

            Understood. Yes, it seems like it was populated wrong.
            I'll check if the trick with /32 as @bingo600 mentioned will work.

            Thank you for your reply's.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.