• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Specific NAT question.

Scheduled Pinned Locked Moved NAT
2 Posts 2 Posters 1.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dlstrout
    last edited by May 28, 2007, 12:33 PM May 28, 2007, 11:21 AM

    I have a specific need to allow clients of a private net (connected to OPT3 w/ 10.10.10.0/24 reserved DHCP addresses) to connect to the LAN net (145.191.112.0/20 > static addresses via DHCP reservations).  BTW only a small supernet of address are attached to the pfS box (145.191.114.0/23).

    The issues is that there are servers in the LAN that the clients of the OPT3 network need access to and these servers REQUIRE 145.191.x.x address to access them.  These admin will NOT allow private address space to access their servers (tcpwrappers, iptables and other SELinux methods).  They are not willing to budge on this ….. so my thinking is that I can set up a NAT pool to NAT the OPT3 addresses (10.10.10.x) to some open LAN address space (145.191.x.x).

    I have tried slicing off a very little subnet 255.255.255.242 of the OPT3 net and doing some 1:1 NAT with these addresses and those of the LAN in the same way, but I have had very little luck.

    QUESTION I
    Is this type of NAT setup even possible?

    QUESTION II
    Do the subnets have to match on either side of the NAT schema?

    QUESTION III
    I am using 1:1 because I want to control which OPT3 clients have access into the LAN (is this correct thinking)?

    QUESTION IV
    Do I have to get the admins of the routable LAN net to carve out a specific subnet for me to use the 1:1 NAT schema?

    QUESTION V
    Do I have to use VIP's and if so what type (Proxy ARP, CARP or plain VIP)?

    QUESTION VI
    Will I have to disable AON (automatic outbound NAT) and create manual outbound NATting to get this configuration working?

    Thanks for you hlp in advance!!

    1 Reply Last reply Reply Quote 0
    • S
      sullrich
      last edited by May 29, 2007, 11:03 PM

      Please do not cross post.  This was sent to the mailing list as well!

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received