Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNAT-DNAT FROM IPSEC VPN TO A PRIVATE NETWORK

    Scheduled Pinned Locked Moved NAT
    3 Posts 2 Posters 524 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      brunoobr
      last edited by

      Hello guys.

      I'm having a bit of a problem on how SNAT-DNAT works. I have a S2S VPN from on on prem client to my Azure instance where there is a PFSense acting as e firewall and S2S VPN.

      The configuration is as follows:

      ON PREM NETWORK IS 172.16.0.0/23
      REMOTE NETWORK IS 192.168.0.0/24 (ON PFSENSE, THIS IS DESIGNED TO BE A NAT ADDRESS)

      ON AZURE(PFSENSE) LOCAL NETWORK IS 10.10.10.4
      INBOUND OR OUTBOUND NAT IS 192.168.100.0.0/24

      SO, TRAFFIC COMMING FROM 172.16.0.15/32 HAS TO GO TO 192.168.100.4.
      AS IT ARRIVES ON PFSENSE, IT WILL BE NATTED TO 10.10.10.4/43.

      Everything is configured, I see traffic going to 10.10.10.4, I see it returning to PFSense but I see no traffic going back to on prem (172.16.0.15).

      For traffic from On prem I used 1:1 NAT

      I'm attaching a diagram with some more details.1eff7b7f-a866-402a-afa6-d59e68adc109.jpg

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @brunoobr
        last edited by

        @brunoobr said in SNAT-DNAT FROM IPSEC VPN TO A PRIVATE NETWORK:

        For traffic from On prem I used 1:1 NAT

        Why?
        You can configure BINAT in the IPSec phase 2.

        1 Reply Last reply Reply Quote 1
        • B
          brunoobr
          last edited by

          Hello @viragomann In fact it works!
          Thanks a whole lot for this tip!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.