Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Solved - Why can i access internet from a subnet not defined in outbound NAT ?

    Scheduled Pinned Locked Moved NAT
    5 Posts 2 Posters 669 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bingo600B
      bingo600
      last edited by bingo600

      pfSense 2.5.2

      Solved ... See Dooh section below ...
      And Johnpoz posts.

      I have a "Mockup/Test" setup , where i have a remote "Lan" 10.138.129.x/24 comming in to my pfSense via a "Connect interface" 10.138.95.1/24

      I'm using a Cisco 1841 , as the "Remote lan" simulator.
      And have just assigned
      fa0/1 - 10.138.95.2/24
      fa0/0 - 10.138.129.1/24

      pfSense routes 10.138.129.0/24 to 10.138.95.2 (Cisco if)
      And Cisco has def-gw on pfSense if - 10.138.95.1

      25b67bc6-7304-4ab4-8653-87887efea64d-image.png

      Why can i access internet from a "Remote lan" device , without having to add the 10.138.129.0/24 net , to Outbound nat ???

      Edit: I'm not doing any NAT/PAT on the CIsco , and wireshark shows it's the 10.138.129.x ip's that hits the pfSense.

      Dooh ... "Polishing my glasses" i see that 10.138.129.0 is defined in outbound NAT via Automatic.

      Where did that come from ???
      I'm 80% sure i did not do that , would not even know how to do it under automatic ....

      /Bingo

      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

      pfSense+ 23.05.1 (ZFS)

      QOTOM-Q355G4 Quad Lan.
      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @bingo600
        last edited by johnpoz

        @bingo600 said in Why can i access internet from a subnet not defined in outbound NAT ?:

        without having to add the 10.138.129.0/24 net

        It is there

        added.jpg

        When you create a route to some downstream network, and your outbound nat is auto.. Then this network gets auto added.

        Example: If I add a route to some downstream network, it is auto added to outbound nat.

        downstream.jpg

        You would still need to make sure that interface that this network comes in on (your transit interface) firewall rules allow it.

        edit: Hybrid is still auto, with the ability to add manual outbound nats.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        bingo600B 1 Reply Last reply Reply Quote 0
        • bingo600B
          bingo600 @johnpoz
          last edited by

          @johnpoz

          Thanx JP
          That was new to me , that the "Downstream route" automatically added outbound nat.

          I lost "Two of my 10 remaining hairs" today ... šŸ¤•

          /Bingo

          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

          pfSense+ 23.05.1 (ZFS)

          QOTOM-Q355G4 Quad Lan.
          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @bingo600
            last edited by

            @bingo600 the magic of pfsense ;)

            Users quite often run into problems when doing downstream network because they have followed some stupid vpn guide somewhere and changed their outbound to manual ;)

            They also normally setup some asymmetrical mess, and using their lan interface as the transit do not alter the lan interface rules from "lan net" etc..

            comming in to my pfSense via a "Connect interface" 10.138.95.1/24

            I see you did it correctly via a "transit"

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            bingo600B 1 Reply Last reply Reply Quote 0
            • bingo600B
              bingo600 @johnpoz
              last edited by

              @johnpoz said in Solved - Why can i access internet from a subnet not defined in outbound NAT ?:

              I see you did it correctly via a "transit"

              šŸ˜‡
              Yepp - I usually have a "Interconnect IF" on my fwalls , all external traffic enters there.
              Well besides WAN , and OVPN.

              Makes Security reviews smooth(er).

              /Bingo

              If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

              pfSense+ 23.05.1 (ZFS)

              QOTOM-Q355G4 Quad Lan.
              CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
              LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.