Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing not working for additional public IPs

    Scheduled Pinned Locked Moved Routing and Multi WAN
    23 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cubits
      last edited by

      Hi,

      I have been using Pfsense+ successfully until now this point where I wanted to route packets to an additional public IP (xx.xx.133.136). My current network setup is like below:

      c82ab6f3-079e-449b-b8b1-679eec7d1bba-image.png

      I tried the steps mentioned in this video: https://www.youtube.com/watch?v=JGZvJOiZ5Tg&t=316s

      But, I am unable to get the packets to the system I wanted via port forwarding.

      Can anyone please help?

      S 1 Reply Last reply Reply Quote 0
      • Cool_CoronaC
        Cool_Corona
        last edited by

        Are they connected to the same NIC port or different ports in the NIC?

        C 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @cubits
          last edited by

          @cubits Along those lines a VIP is the typical way to accomplish this:
          https://docs.netgate.com/pfsense/en/latest/firewall/virtual-ip-addresses.html
          Then use either 1:1 NAT or outbound NAT to control the outbound connections. (1:1 automatically sets up outbound)

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote ๐Ÿ‘ helpful posts!

          C 1 Reply Last reply Reply Quote 0
          • C
            cubits @SteveITS
            last edited by

            @SteveITS I tried that, but without outbound, I think I should not use 1:1 NAT and would like to only use a port forwarding, which I think is more secure than letting everything?

            S 1 Reply Last reply Reply Quote 0
            • C
              cubits @Cool_Corona
              last edited by

              @Cool_Corona same NIC I believe, the ISP people do have not much idea unless I really escalate to the top. I thought I will check here rather.

              Cool_CoronaC 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @cubits
                last edited by

                @cubits You can use port forwarding for inbound.

                What exactly isnโ€™t working? Can you show the VIP configuration?

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                C 1 Reply Last reply Reply Quote 0
                • Cool_CoronaC
                  Cool_Corona @cubits
                  last edited by

                  @cubits said in Routing not working for additional public IPs:

                  @Cool_Corona same NIC I believe, the ISP people do have not much idea unless I really escalate to the top. I thought I will check here rather.

                  Using 1 port only or does the nic have multiple ports?

                  C 1 Reply Last reply Reply Quote 0
                  • C
                    cubits @Cool_Corona
                    last edited by

                    @Cool_Corona one NIC only

                    1 Reply Last reply Reply Quote 0
                    • C
                      cubits @SteveITS
                      last edited by cubits

                      @SteveITS
                      308956ef-a085-4f07-8a8d-803e7eb1c343-image.png
                      eb5d62e6-1a01-48a9-8d8f-b1d180a47c50-image.png
                      144cc51d-bb25-462b-9d24-6b6b62823fa9-image.png

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        SteveITS Galactic Empire @cubits
                        last edited by

                        @cubits Does outbound work from that server 10.110.0.22? Is there a firewall on that server and does it allow packets from outside its subnet?

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote ๐Ÿ‘ helpful posts!

                        C 1 Reply Last reply Reply Quote 0
                        • C
                          cubits @SteveITS
                          last edited by

                          @SteveITS i have a port forwarding to this server on the main IP and it works fine.

                          S 1 Reply Last reply Reply Quote 0
                          • S
                            SteveITS Galactic Empire @cubits
                            last edited by

                            @cubits If you allow ICMP to the alias IP can you ping it or traceroute it from something on the Internet?

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote ๐Ÿ‘ helpful posts!

                            C 1 Reply Last reply Reply Quote 0
                            • C
                              cubits @SteveITS
                              last edited by cubits

                              @SteveITS I did the ICMP, and the main IP is pingable and tracerouteable. The additional IP on traceroute gives destination host unreachable from another host which is not present in the route of the main IP.

                              S 1 Reply Last reply Reply Quote 0
                              • S
                                SteveITS Galactic Empire @cubits
                                last edited by

                                @cubits It should be. If the inbound traceroutes use different paths, maybe your ISP is not routing your entire /24 block to you?

                                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                Upvote ๐Ÿ‘ helpful posts!

                                C 2 Replies Last reply Reply Quote 0
                                • C
                                  cubits @SteveITS
                                  last edited by

                                  @SteveITS It should be very well correct. It is just one IP in the subnet and other users might be using other IPs from the same subnet.

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    cubits @SteveITS
                                    last edited by

                                    @SteveITS how to get around this?

                                    S 1 Reply Last reply Reply Quote 0
                                    • S
                                      SteveITS Galactic Empire @cubits
                                      last edited by

                                      @cubits said in Routing not working for additional public IPs:

                                      other users might be using other IPs from the same subnet.

                                      ? They can't if it's your subnet. Are these only two unrelated/not-consecutive IPs and not a subnet block? I suppose that would work but the inbound routing still needs to go through the same router as your original IP, to get to you.

                                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                      Upvote ๐Ÿ‘ helpful posts!

                                      C 3 Replies Last reply Reply Quote 0
                                      • C
                                        cubits @SteveITS
                                        last edited by

                                        @SteveITS just wanted to confirm that, and that's exactly what I thought about it, at least it should route new IP until the original IP, I will contact them and discuss further and post back later.

                                        1 Reply Last reply Reply Quote 0
                                        • C
                                          cubits @SteveITS
                                          last edited by

                                          @SteveITS spoke to the network engineer from ISP and he asked to place a switch between wan and pfsense, and connect them to separate NIC as the whole block of IP is not forwarded. I have orderd the hardware and will test and let know here.

                                          1 Reply Last reply Reply Quote 0
                                          • C
                                            cubits @SteveITS
                                            last edited by

                                            @SteveITS I have updated my setup like below. I had to use a router as both IPs since they are on the same subnet couldnt be used in the PFSENSE. As it is now, I can ping the router default gateway from within PFSENSE, but not from my LAN or by any OpenVPN client.

                                            5003c2e4-b6aa-46ff-86af-60e64883a7f0-image.png

                                            S 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.