<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Am I missing an outbound NAT rule?]]></title><description><![CDATA[<p dir="auto">In my testing configuration, LAN is 192.168.11.0/24, and WAN is 192.168.0.0/24. See the attached pictures for configuration details. Basically, I want to be able to forward from 192.168.0.202:80 (a CARP IP address) to 192.168.11.4:80. The web server is definitely running, because it serves pages on its 192.168.11.4 address. Its firewall is set to allow all traffic. For instance, I can telnet from pfsense to 192.168.11.4:80.</p>
<p dir="auto">On the web server, I can run tcpdump -i any -w 80.pcap 'tcp port 80', which yields 2 incoming "HTTP [SYN]" packets, and no outbound traffic. This is also exactly the traffic the MASTER pfsense router sees. The slave sees no port 80 traffic, as you would expect.<br />
![firewall forwarding.png](/public/<em>imported_attachments</em>/1/firewall forwarding.png)<br />
![firewall forwarding.png_thumb](/public/<em>imported_attachments</em>/1/firewall forwarding.png_thumb)<br />
![firewall outbound.png](/public/<em>imported_attachments</em>/1/firewall outbound.png)<br />
![firewall outbound.png_thumb](/public/<em>imported_attachments</em>/1/firewall outbound.png_thumb)<br />
![firewall rules.png](/public/<em>imported_attachments</em>/1/firewall rules.png)<br />
![firewall rules.png_thumb](/public/<em>imported_attachments</em>/1/firewall rules.png_thumb)<br />
![firewall virtual ip.png](/public/<em>imported_attachments</em>/1/firewall virtual ip.png)<br />
![firewall virtual ip.png_thumb](/public/<em>imported_attachments</em>/1/firewall virtual ip.png_thumb)<br />
<img src="/public/_imported_attachments_/1/routes.png" alt="routes.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/routes.png_thumb" alt="routes.png_thumb" class=" img-fluid img-markdown" /><br />
![web server packet capture.png](/public/<em>imported_attachments</em>/1/web server packet capture.png)<br />
![web server packet capture.png_thumb](/public/<em>imported_attachments</em>/1/web server packet capture.png_thumb)<br />
![carp status.png](/public/<em>imported_attachments</em>/1/carp status.png)<br />
![carp status.png_thumb](/public/<em>imported_attachments</em>/1/carp status.png_thumb)</p>
]]></description><link>https://forum.netgate.com/topic/45054/am-i-missing-an-outbound-nat-rule</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Apr 2026 20:36:07 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/45054.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 17 May 2012 17:14:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Am I missing an outbound NAT rule? on Thu, 17 May 2012 17:40:24 GMT]]></title><description><![CDATA[<p dir="auto">This turned out to be a problem due to the web server having an interface on the 192.168.0.0/24 network. Taking that interface down allowed packets to flow freely, how they were meant to.</p>
]]></description><link>https://forum.netgate.com/post/336975</link><guid isPermaLink="true">https://forum.netgate.com/post/336975</guid><dc:creator><![CDATA[jeff]]></dc:creator><pubDate>Thu, 17 May 2012 17:40:24 GMT</pubDate></item></channel></rss>