Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT exemption

    Scheduled Pinned Locked Moved NAT
    5 Posts 2 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nmneves
      last edited by

      Hello.

      I'm trying to setup pfsense and although everything seems to be running smooth, I do have a problem:

      My WAN connection is a /29 address, in which I have some servers (let's call it a DMZ)
      I then have several internal networks (VLANs), and I would like to setup pfsense so that when an internal machine tries to reach my DMZ, it is exempt from NAT.

      I already tried to add a new rule in the Outbound section of NAT, but with no success. Has anyone else managed to get this configuration working?

      Thank you,

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Can you show a screenshot of the rules you tried?

        Do your servers in the DMZ know the route back to these VLANs?
        Otherwise they don't know where to send a response to a request.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • N
          nmneves
          last edited by

          I attach my firewall rule.

          As for the route, yes, the DMZ servers have the route back.

          I just don't now how to do the exemption from pfsense. Also, looking directly with pfctl (which I am not familiar with, being an iptables guy  :)), I can't seem to find this rule.

          Anyone else tried this scenario?

          Thank you,

          Capture.GIF
          Capture.GIF_thumb

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            You've set the interface to LAN.
            However outbound rules are applied on the interface on which traffic leaves.
            So this should be your DMZ interface.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • N
              nmneves
              last edited by

              I had already tried it, but changed it again.

              Then, from an internal machine, I try to access DMZ (which is also WAN for pfsense) but it still translates.

              One thing I noted, if I run "pfctl -s all" I can not see this rule. It appears it doesn't get applied.

              Since I am away, I will not try a reboot now  :P, but do you think this may be it?

              Is there a command line version of this so that I can try "manually"?

              Thank you again

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.