Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ISP gave my company layer2 handoff and two sets of IPs… Now what?

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 5 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      AkkerKid
      last edited by

      My ISP just finalized installing the fiber in my building and gave me two sets of IPs.  One for my firewall and a set for my devices.
      The way the installer said it to me is that I have to set the WAN of my router/firewall to xx.xx.xx.2 and the gateway to xx.xx.xx.1 and then route the other subnet through that.  The second subnet is zz.zz.zz.64 to zz.zz.zz.96 (/27)
      I know that if I set the WAN to the xx numbers, all of my outbound internet requests will be coming from the xx ip.  But if I want them to come from one of the zz ips, what do I do?  Set up virtual IPs? Set up static routes?  Build some kind of internal loop after effectively breaking the router into two parts, one as the gateway and one as the router/firewall?

      Stats:
      Version: 1.2.3-RELEASE
      Intel Atom D525 1.8GHz Dual core
      4GB RAM
      Dual GBE plus a 100MB PCI card

      Is pfSense no longer appropriate for my topology?  :-
      Thanks in advance!
      –AkkerKid

      1 Reply Last reply Reply Quote 0
      • N
        Nachtfalke
        last edited by

        I am not 100% sure but probably you have to use manual outbound NAT for that.

        1 Reply Last reply Reply Quote 0
        • W
          wallabybob
          last edited by

          This kind of configuration is described in the book pfSense: The Definitive Guide through chapters 6, 7 and 8 and particularly in section 6.7 (Methods of using additional public IPs).

          1 Reply Last reply Reply Quote 0
          • dotdashD
            dotdash
            last edited by

            1. Upgrade to 2.0.1 already.
            2. Depending on the ISP setup, you could add a WAN alias on the /27 and then add VIPs, or just add the VIPs.
            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Are xxx and zzz both public subnets?

              Steve

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.