Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    NAT Port forward with a source address network alias stopped working for networks other then /32

    Scheduled Pinned Locked Moved NAT
    4 Posts 3 Posters 356 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      Mikeb 0
      last edited by

      Netgate 8200 24.11 with HA pair
      Was working great.
      Had to restart the routers over the weekend.
      After the restart, any network in the alias with a network mask other than /32 stopped working.
      Sometimes recreating the network in the alias works, other times it does not.
      I exported the list to a file and then imported it as a new network list and changed the NAT rule to use the new alias.
      Under the new alias, I still have a few networks that don't work.
      I can see the block on the router in the default deny rule and see the network subnet in the alias list.
      I fixed a small network block by adding all the IPs as separate /32 lines.

      Any ideas on how to fix this?

      johnpozJ SteveITSS 2 Replies Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator @Mikeb 0
        last edited by johnpoz

        @Mikeb-0 first thing I would suggest is get current 24.. Almost 2 years old?

        26.03.1 is current 26.07 should be out soon.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

        1 Reply Last reply Reply Quote 0
        • SteveITSS Offline
          SteveITS Rebel Alliance @Mikeb 0
          last edited by

          @Mikeb-0 do you by chance have a lot of/big aliases?
          https://docs.netgate.com/pfsense/en/latest/config/advanced-firewall-nat.html#firewall-maximum-table-entries

          To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
          Only install packages for your version of pfSense.
          Upvote 👍 helpful posts!

          M 1 Reply Last reply Reply Quote 0
          • M Offline
            Mikeb 0 @SteveITS
            last edited by

            @SteveITS
            I have 102 lines
            3 /24
            1 /16
            2 /27
            1 /28
            2 /29

            The rest are /32
            Not a lot.
            It was all working until the reboot.
            Then all the lines we set to /32
            I updated the incorrect records.
            It seems the lines with anything but a /32 were working.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
            Privacy Policy · Cookie Policy