Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot disable NAT on PFSense 2.7.2 CE

    Scheduled Pinned Locked Moved NAT
    natcannot disable
    4 Posts 2 Posters 428 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      BlueSun
      last edited by BlueSun

      On PFsense 2.7.2 CE (206.x.y.41/29), I have BGP running, and setup some hosts on the BGP subnet. For some strange reason, I cannot NAT disabled. Hence, when host on one of the other public IP subnets (196.x.y.70/26 or 196.x.y.66/26) connects to the internet, is is seen as the internet gateway, i.e. 206.x.y.41/29.

      This causes major issues as the traffic is NAT'ed. cPanel, for example cannot license the server as
      the wrong IP comes up.

      75d25dcb-bcc0-43d4-aca8-645076340fab-image.png

      e7d7a9d4-b82a-43ce-8ed3-fe63be25aa2b-image.png

      33baf50a-4492-4afe-946c-28b812308f24-image.png

      patient0P 1 Reply Last reply Reply Quote 0
      • patient0P Offline
        patient0 @BlueSun
        last edited by

        @BlueSun said in Cannot disable NAT on PFSense 2.7.2 CE:

        setup some hosts on the BGP subnet

        If you set a gateway in the interface settings, pfSense automatically creates a NAT rule for that subnet. Have you set one for the BGP subnet?

        Netgate pfSense docu: Default NAT Configuration:

        "For detecting WAN-type interfaces for use with NAT, pfSense software looks for the presence of a gateway selected on the interface configuration if it has a static IP address,..."

        B 1 Reply Last reply Reply Quote 0
        • B Offline
          BlueSun @patient0
          last edited by

          @patient0 said in Cannot disable NAT on PFSense 2.7.2 CE:

          @BlueSun said in Cannot disable NAT on PFSense 2.7.2 CE:

          setup some hosts on the BGP subnet

          If you set a gateway in the interface settings, pfSense automatically creates a NAT rule for that subnet. Have you set one for the BGP subnet?

          Netgate pfSense docu: Default NAT Configuration:

          "For detecting WAN-type interfaces for use with NAT, pfSense software looks for the presence of a gateway selected on the interface configuration if it has a static IP address,..."

          I have setup a default gateway for the BGP subnet.

          ee9b0d72-8065-4280-a41d-1437ca1e5448-image.png

          843ad537-1878-47fb-af64-0ea9bdaaca88-image.png

          patient0P 1 Reply Last reply Reply Quote 0
          • patient0P Offline
            patient0 @BlueSun
            last edited by

            @BlueSun ok, I'm generally out of my depth in regards to BGP.

            All I can say if you set a gateway in the interface settings (see screenshot) then pfSense creates NAT rules automatically, if outbound NAT is set to automatic or hybrid.

            Screenshot 2025-08-14 at 18.25.56.png

            But since you have disable outbound NAT I can't see your traffic being NAT-ted at all.

            Are you using the FRR packages and if yes did you have a look at pfSense Docu: BGP Example Configuraton for a start?

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.