    i am trying to understand the 1:1 NAT feature in pfsense. here is my basic configuration:

                 red-PC---------------------| pfSense |
    GW:                                                                                                           GW:

    firewall: pass all red<>green
    ping between red-PC und green-PC is working.
    2.0-RELEASE (i386)

    what i understand : with 1:1 nat i can reach the green-PC by using an IP adress which is not in
    on red-PC:    >ping

    ping should be replied by - is that correct ?
    destination IP will be mapped to destination IP

    but the ping fails ! any ideas ?

    next question:
    in the green subnet, is a PC with IP =
    is it possible to reach this PC from red-PC by using 1:1 NAT ?

    thanks for your support !

  • according to your network design the 192.168.12 is not a valid subnet on your LAN. Unless you setup a VIP to proxy for it, the firewall will do nothing with it but block or forward nowhere.

  • Yes !

    i added a virtual ip address-range on the red port.
    but this will not help. which type should i use ?

    It Works !
                  red-PC---------------------| pfSense |

    S:  >>>>>>>>>>>>>>request >>>>>>>>>>>>>>>>>>>>>>  S:
          D: >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>    D:

    S:  <<<<<<<<<<<<<reply<<<<<<<<<<<<<<<<<<<<<<<<<  S:
      D:  <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<  D:

    </reply<<<<<<<<<<<<<<<<<<<<<<<<< >

  • to complete this threat:
    by adding a virtual ip range ( also on green port, and changing the 1:1 nat rule (Internal IP =  the following is possible:

    red-PC–-------------------| pfSense |


    S:          >>>>>>>>>>>>>>request >>>>>>>>>>>>>>>>> >>>>>  S:
          D:    >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>    D:

    S:        <<<<<<<<<<<<<<<<<reply<<<<<<<<<<<<<<<<<<<<  S:
      D:            <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<  D:


    S:  >>>>>>>>>>>>>>request >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> >>>>>  S:
          D: >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>    D:

    S:  <<<<<<<<<<<<<<<<<<<<<<<<<<<<reply<<<<<<<<<<<<<<<<<<<<<<<<<<<   S:
      D:  <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<  D:

    ping will not work

