NAT Port forward with a source address network alias stopped working for networks other then /32
-
Netgate 8200 24.11 with HA pair
Was working great.
Had to restart the routers over the weekend.
After the restart, any network in the alias with a network mask other than /32 stopped working.
Sometimes recreating the network in the alias works, other times it does not.
I exported the list to a file and then imported it as a new network list and changed the NAT rule to use the new alias.
Under the new alias, I still have a few networks that don't work.
I can see the block on the router in the default deny rule and see the network subnet in the alias list.
I fixed a small network block by adding all the IPs as separate /32 lines.Any ideas on how to fix this?
-
@Mikeb-0 first thing I would suggest is get current 24.. Almost 2 years old?
26.03.1 is current 26.07 should be out soon.
-
@Mikeb-0 do you by chance have a lot of/big aliases?
https://docs.netgate.com/pfsense/en/latest/config/advanced-firewall-nat.html#firewall-maximum-table-entries -
@SteveITS
I have 102 lines
3 /24
1 /16
2 /27
1 /28
2 /29The rest are /32
Not a lot.
It was all working until the reboot.
Then all the lines we set to /32
I updated the incorrect records.
It seems the lines with anything but a /32 were working.
Privacy Policy · Cookie Policy