Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Source IP based on Destination IP (weird question)

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    3 Posts 2 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Achromatic
      last edited by

      Note: please move if need be.

      So, I have a /29 from my ISP, with reverse dns on several of the IP addresses, of the form 'host.personaldomain.com'.

      For connecting to work and client servers that are not across our VPN (most are, but some aren't), I'd like to use one of the IP addresses as a 'generic', so it will show up in the usual 'ip-ad-dr-ess-washington.hfc.comcastbusiness.net' rather than 'host.personaldomain.com'.

      The list is small so I could maintain it manually as an alias, approximately a dozen IP addresses.

      I don't want to use 1:1 NAT, because there are several machines here that could be used.

      How would I, if indeed I even could, go about writing a rule that says 'when remote host is in alias list x, use this IP address for outbound'? All the requisite IPs are assigned to the firewall as Proxy ARP virtuals.

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG Offline
        GruensFroeschli
        last edited by

        firewall –> NAT --> outbound.

        Here you can create manual outbound rules.
        --> source-IP based NAT like you describe it.

        But unfortunately it's not possible to use aliases here :(
        Maybe you could arrange your IP's so the can use rules like:
        Your subnet: /24
        Over_devault_WAN: /22
        Over_VIP1: /22
        Over_VIP2: /22
        Over_VIP3: /22

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • A Offline
          Achromatic
          last edited by

          That seems like it would work well, thanks! I will give it a try today.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.