• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

how to map multiple addresses provided by isp in pfsense

Scheduled Pinned Locked Moved General pfSense Questions
9 Posts 4 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H
    hardikpfsense
    last edited by Aug 12, 2022, 8:43 AM

    Hello,

    our isp provides us 3 static address. so the main address is set as wan ip. i want to use another two static address provided by isp to map it to my local network. I don't where i can add them in pfsense. can anyone point me to any of the documentation or tutorial?

    N 1 Reply Last reply Aug 12, 2022, 8:50 AM Reply Quote 0
    • N
      NogBadTheBad @hardikpfsense
      last edited by Aug 12, 2022, 8:50 AM

      @hardikpfsense Are the IP addresses in the same subnet range ?

      If they are you'd do a 1:1 NAT:-

      https://docs.netgate.com/pfsense/en/latest/nat/1-1.html#configuring-1-1-nat

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      H 1 Reply Last reply Aug 12, 2022, 9:02 AM Reply Quote 0
      • H
        hardikpfsense @NogBadTheBad
        last edited by hardikpfsense Aug 12, 2022, 9:02 AM Aug 12, 2022, 9:02 AM

        @nogbadthebad said in how to map multiple addresses provided by isp in pfsense:

        https://docs.netgate.com/pfsense/en/latest/nat/1-1.html#configuring-1-1-nat

        Okay this is what our isp sent us.

        WAN

        IP - 103.xx.xx.14

        Sub net - 255.255.255.252

        Gateway - 103.xx.xx.13


        Public IP Pool - 103.xx.xx.96/29

        Network - 103.xx.xx.96

        Gateway - 103.xx.xx.97

        Broadcast - 103.xx.xx.103

        Usable - 103.xx.xx.98 - 103.xx.xx.102

        that is why i am bit confused here. how do i use this ? can i directly use 103.xx.xx.98 and do 1:1 mapping

        N V 2 Replies Last reply Aug 12, 2022, 9:08 AM Reply Quote 0
        • N
          NogBadTheBad @hardikpfsense
          last edited by NogBadTheBad Aug 12, 2022, 9:10 AM Aug 12, 2022, 9:08 AM

          @hardikpfsense If you do a traceroute from the internet to 103.xx.xx.98 does it route via the WAN interface.

          You'll probally need to set up the 103.xx.xx.96/29 as a new LAN interface and don't NAT.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          H 1 Reply Last reply Aug 12, 2022, 9:14 AM Reply Quote 0
          • H
            hardikpfsense @NogBadTheBad
            last edited by hardikpfsense Aug 12, 2022, 9:14 AM Aug 12, 2022, 9:14 AM

            @nogbadthebad said in how to map multiple addresses provided by isp in pfsense:

            If you do a traceroute from the internet to 103.xx.xx.98 does it route via the WAN interface.

            Nope. it does not.

            You'll probally need to set up the 103.xx.xx.96/29 as a new LAN interface and don't NAT.

            our current wan interface is set as 103.xx.xx.14
            our current lan interface is set as 192.168.1.1

            We only have two ports so we can only set two interfaces. so not sure how we can add lan interface here. if i go to Interfaces > Interface Assignments. there is only two interfaces wan and lan and it does not allow me to add another one.

            N 1 Reply Last reply Aug 12, 2022, 9:16 AM Reply Quote 0
            • N
              NogBadTheBad @hardikpfsense
              last edited by NogBadTheBad Aug 12, 2022, 9:17 AM Aug 12, 2022, 9:16 AM

              @hardikpfsense You'll need to add an extra LAN port and switch or use a switch that can handle VLANS.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              H 1 Reply Last reply Aug 12, 2022, 9:28 AM Reply Quote 0
              • H
                hardikpfsense @NogBadTheBad
                last edited by Aug 12, 2022, 9:28 AM

                @nogbadthebad

                Thank you sir. just for my knowledge i am asking this. if everything is done via wan port how this lan interface we will add translate from wan port ?

                1 Reply Last reply Reply Quote 0
                • V
                  viragomann @hardikpfsense
                  last edited by Aug 12, 2022, 9:45 AM

                  @hardikpfsense said in how to map multiple addresses provided by isp in pfsense:

                  Okay this is what our isp sent us.

                  The question is if the additional /29 subnet is routed to the primary WAN IP.
                  If so you only need to nat the IPs behind pfSense or nat outbound traffic to them.
                  The gateway of the /29 wouldn't be needed in this case.

                  However, since the IP stated a gateway, I assume, it's a real subnet and is not routed.

                  In this case you can try this: add each usable IP out of the /29 subnet as virtual IP to WAN. Firewall > Virtual IPs. Use type "IP alias" and ensure to state the proper /29 mask.
                  Then go to System > Routing > Gateways and add the gateway 103.xx.xx.97 to WAN interface.

                  However, pfSense will use the default gateway for the communication with all IPs as long as you don't add special routes for the other gateway as far as I know.
                  So it's on the settings of the ISPs gateway to accept packets from the other subnet. Normally it does.

                  1 Reply Last reply Reply Quote 0
                  • S
                    stephenw10 Netgate Administrator
                    last edited by Aug 12, 2022, 12:40 PM

                    It would be much better if the ISP did route the /29 to you via the WAN IP. A much more flexible setup. You might want to contact them and ask if they can do that.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    6 out of 9
                    • First post
                      6/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received