Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Nat/firewall, not sure exactly

    Scheduled Pinned Locked Moved NAT
    2 Posts 1 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cubsfan
      last edited by

      Wasn't real sure where to post this one

      I have a somewhat odd setup on a couple pf boxes, I will draw it the best I can

      pf2  -> LAN
                              |
      internet -> pf1
                              |
                              pf3  -> LAN
                                |
                              netA

      I'm trying to nat from the public side of pf2 to a host on netA through the LAN subnet.  I was thinking I could setup a firewall rule on the netA interface of pf3 to change the gateway to the LAN interface of pf2 and accomplish it but it's still trying to send the replies out  the WAN interface of pf3.  pf3 has NAT enabled for netA on the wan interface so I'm not sure if that is hitting before the LAN rule and sending it out that way or what is happening exactly.

      Is there any way to accomplish this?

      thanks

      1 Reply Last reply Reply Quote 0
      • C
        cubsfan
        last edited by

        @cubsfan:

        Wasn't real sure where to post this one

        I have a somewhat odd setup on a couple pf boxes, I will draw it the best I can

        pf2   -> LAN
                                 |
        internet -> pf1
                                 |
                                pf3   -> LAN
                                  |
                                netA

        I'm trying to nat from the public side of pf2 to a host on netA through the LAN subnet.  I was thinking I could setup a firewall rule on the netA interface of pf3 to change the gateway to the LAN interface of pf2 and accomplish it but it's still trying to send the replies out  the WAN interface of pf3.  pf3 has NAT enabled for netA on the wan interface so I'm not sure if that is hitting before the LAN rule and sending it out that way or what is happening exactly.

        Is there any way to accomplish this?

        thanks

        Also, with the policy rule in place, traffic is sent to pf2 from the host on netA I'm trying to do this with, it's just the replies that don't seem to be routed back out that way.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.