• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Help with Multi-WAN, additional routed IP Block

Scheduled Pinned Locked Moved Routing and Multi WAN
8 Posts 3 Posters 2.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    althornin
    last edited by Jan 10, 2012, 6:18 PM

    Hey guys,
    I've been beating my head against this for a while today, and I just can't seem to get it to work the way I expect.

    Basics:
    Running pfsense 2.0.1
    I have a multi-WAN setup.  All of that works fine.
    Some of the WAN links are actually subnets, and I can create VIPs and NAT on those additional IPs appropriately.

    One of the WAN links is new, and is only a /30 (for routing purposes only).  The IP is 38.104.aaa.bbb
    I have been assigned a block of IP addresses (38.110.xxx.yyy/28) that is routed to me through the above wan link.

    I want to be able to create VIPs in this new block, and NAT them accordingly to use various services through the public IPs.  However, my attempts to do so have failed.

    What is the appropriate method to do this?

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Jan 10, 2012, 7:45 PM

      Using 'other' type VIPs for this should work fine, or even proxy ARP, or IP alias would work.

      As they are routed to you, they'll hit the router no matter which type you choose.

      So what didn't work when you tried?

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • A
        althornin
        last edited by Jan 10, 2012, 7:58 PM

        @jimp:

        Using 'other' type VIPs for this should work fine, or even proxy ARP, or IP alias would work.

        As they are routed to you, they'll hit the router no matter which type you choose.

        So what didn't work when you tried?

        Well, that worked fine.
        I was trying to use CARP VIPs, which require to match an interface subnet, so i was trying to create a new interface containing the subnet and route it through the new WAN connection.
        All in all, making it vastly more complicated.

        However, what if I do need CARP?  What can I do then?

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Jan 10, 2012, 8:04 PM

          Add one IP Alias VIP to get a foothold in the new subnet (for each CARP node), then you can add the rest as CARP VIPs.

          That gets you the required address inside the subnet that CARP wants.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • A
            althornin
            last edited by Jan 10, 2012, 8:27 PM

            @jimp:

            Add one IP Alias VIP to get a foothold in the new subnet (for each CARP node), then you can add the rest as CARP VIPs.

            That gets you the required address inside the subnet that CARP wants.

            Ok, thanks!

            And much simpler than the craptastic way I was trying to do this.

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by Jan 10, 2012, 11:46 PM

              For routed subnets, you do not want VIPs (other than type Other), just have them routed to a CARP IP on your main IP block.

              1 Reply Last reply Reply Quote 0
              • J
                jimp Rebel Alliance Developer Netgate
                last edited by Jan 10, 2012, 11:49 PM

                Unless you want to bind services to them with something like relayd, but otherwise yeah, Other on its own is best if they're just for NAT.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • A
                  althornin
                  last edited by Jan 11, 2012, 1:05 PM

                  @cmb:

                  For routed subnets, you do not want VIPs (other than type Other), just have them routed to a CARP IP on your main IP block.

                  Ok, great.

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received