• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

NAT vpn if connection to a specific host.

Scheduled Pinned Locked Moved General pfSense Questions
5 Posts 3 Posters 672 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    swansense
    last edited by Dec 19, 2021, 12:53 PM

    I have a VPN Server configured on Pfsense so i can access my home when im out and it works perfect.

    The problem I have is i have a machine on my network that i have limited control over, this VNC machine only allows access to it on its local subnet so i am not able to access it via VPN. The problem is when im out and about i can access my environment over VPN but i can not access this unless i RDP to another machine or something.

    Is it possible to configure Pfsense to NAT the connection and use a local lan IP when NATing if i a connection from the VPN network is trying to access this machine.

    I want to be able to configure a Pfsense to Nat the connect to the machine so the VNC machine thinks the traffic is coming from my local network and not my VPN network. the only port i really needed NAT'd is vnc port 5900

    so here is what i am trying to achieve using info i found on other threads
    Vpn network 10.99.8.0/24 ---> Nat traffic to 192.168.0.0/24 ---> VNC Machines 192.168.0.85

    I have tired a few different things but not really sure where to start.

    Here was one attempt but it doesnt work. Im not sure in this case what type of NAT i should be using so any help will be appreciated.

    [img]https://i.imgur.com/sG6HJEs.png[/img]

    J J 2 Replies Last reply Dec 19, 2021, 2:15 PM Reply Quote 0
    • J
      JKnott @swansense
      last edited by Dec 19, 2021, 2:15 PM

      @swansense

      Perhaps you could try OpenVPN tap mode, which is essentially a bridge between the 2 sites.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator @swansense
        last edited by johnpoz Dec 19, 2021, 2:45 PM Dec 19, 2021, 2:32 PM

        @swansense said in NAT vpn if connection to a specific host.:

        Is it possible to configure Pfsense to NAT the connection and use a local lan IP when NATing if i a connection from the VPN network is trying to access this machine.

        Yeah you can do that, just create a outbound nat on the interface this device is on, lan I would assume. With destination to that specific IP source of your vpn tunnel network, using the lan address as the address.

        This will make it look like to the device your coming from your pfsense lan IP vs the IP of the vpn client tunnel network IP.

        If need be I could setup an example with my vpn showing you pictures..

        edit: Here you go just did example anyway. So pfsense lan IP is 192.168.9.253, my tunnel network for vpn is 10.0.200/24 - so at first you can see my vpn client pinging host on my lan network 192.168.9.100 coming from 10.0.200.250..

        I then created the outbound nat on the lan interface. Now the pings come from pfsense IP vs the vpn client IP.

        example.jpg

        You could get specific with the destination, for example I could of used specific 192.168.9.100/32 as the destination vs the whole network..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        S 1 Reply Last reply Dec 20, 2021, 10:13 AM Reply Quote 2
        • S
          swansense @johnpoz
          last edited by Dec 20, 2021, 10:13 AM

          @johnpoz

          wow that was a lot easier than i expected.

          thanks so much I literally spent days trying to figure this out and it worked without any issues.

          Thanks again and happy holidays.

          J 1 Reply Last reply Dec 20, 2021, 12:41 PM Reply Quote 1
          • J
            johnpoz LAYER 8 Global Moderator @swansense
            last edited by Dec 20, 2021, 12:41 PM

            @swansense said in NAT vpn if connection to a specific host.:

            Thanks again and happy holidays.

            No problem - and a happy holidays to you as well..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received