• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Anyway to implement DNAT and SNAT?

Scheduled Pinned Locked Moved NAT
5 Posts 2 Posters 3.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dparsons
    last edited by Aug 6, 2010, 1:22 PM

    What I need is a rule that looks like this:

    TYPE  NET1                IFACE        NET2 
    SNAT  192.168.1.0/24 vpn              10.10.11.0/24       
    DNAT  10.10.11.0/24  vpn              192.168.1.0/24

    This is to overcome a network duplication issue where the people VPNing into my network have the same subnet as my internal network.

    1 Reply Last reply Reply Quote 0
    • C
      cmb
      last edited by Aug 7, 2010, 10:14 PM

      Depends on the type of VPN. IPsec, no, not without a separate box to do NAT. OpenVPN yes.

      1 Reply Last reply Reply Quote 0
      • D
        dparsons
        last edited by Aug 9, 2010, 11:23 AM

        Yes I am using OpenVPN so that is certainly good news!  Do you happen to have a doc on how to achieve this?  While I have found information on google about doing this it almost always involves using iptables to set it up correctly.

        Thanks!

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by Aug 10, 2010, 12:24 AM

          Only place I know of it being covered is in the book. http://pfsense.org/book

          In short, assign your OpenVPN interfaces, then do NAT on them like any other interface. That's partially covered on the doc site, check the OpenVPN category at doc.pfsense.org.

          1 Reply Last reply Reply Quote 0
          • D
            dparsons
            last edited by Aug 10, 2010, 11:36 AM

            Thanks!

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received