Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Outbound Nat only 1/2 working

    NAT
    3
    6
    742
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      CHSTECHSOLUTIONS
      last edited by

      I have a web server behind my Netgate 6600 router.

      I have 2 IP addresses on this router Address A is the one on the wan interface and Address 2 is a virtual IP.

      I need ALL the traffic of this webserver to go out over a Virtual IT address.

      I have the following outbound nat rule in place.
      Screen Shot 2022-05-13 at 3.42.34 PM.png

      I can not use a 1:1 nat as I need other services on this IP address to go to other servers.

      I also have inbound rules for the services (http/s, email, FTP...) these all seem to be working properly

      I can run curl api.ipify.org and I get IP address 2 but when I send an email from the server all the headers say it is coming from IP Address 2.

      This is causing issues with spam and other stuff. What am i doing wrong? Please let me know if you need more information

      S V 2 Replies Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @CHSTECHSOLUTIONS
        last edited by

        @chstechsolutions Could that server have open connections/states already using the other IP? I would think a new SMTP connection would be new but you might double check.

        It's set to Hybrid Outbound NAT?

        The inbound is different, the outbound rule has no effect on inbound NAT forwards.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        C 1 Reply Last reply Reply Quote 0
        • C
          CHSTECHSOLUTIONS @SteveITS
          last edited by

          @steveits Hybrid Nat is selected.

          I have reset booted the router and the server a few times. even at the same time. that should have "fix" and open connections.

          And correct. the inbound rule is working properly. this issue is only on the outbound rule. new messages that come in over port 25 or other email ports all go to this server successfully. if is only outbound email connections that have this problem.

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @CHSTECHSOLUTIONS
            last edited by

            @chstechsolutions Is the alias correct? Web server doesn't have multiple IPs, or IPv6?

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            C 1 Reply Last reply Reply Quote 0
            • C
              CHSTECHSOLUTIONS @SteveITS
              last edited by

              @steveits I assume that alias is correct. it is working for all inbound rules.

              The server has qpv6 disabled and only one IP. I just checked that myself.

              1 Reply Last reply Reply Quote 0
              • V
                viragomann @CHSTECHSOLUTIONS
                last edited by

                @chstechsolutions said in Outbound Nat only 1/2 working:

                I can run curl api.ipify.org and I get IP address 2 but when I send an email from the server all the headers say it is coming from IP Address 2.

                Isn't this what you want and what the outbound NAT rule is meant to do?

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.