<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[1:1 NAT]]></title><description><![CDATA[<p dir="auto">Generally speaking, I'm pretty good with VPN's and NAT and all the networking stuff. But for some reason I'm having trouble with this.</p>
<p dir="auto">Oversimplified description:<br />
I have a pfsense device whose sole function is to do NAT between a 10.x.x.x/24 network, and a 192.168.x.x/24 network.  I connected the WAN side to 10.x.x.x/24, and the LAN is 192.168.x.x/24.  Ideally, I would like a range of IP's to be 1:1 nat'd in both directions, and all traffic passed.  But since that was proving more difficult than expected, I'm aiming low now, just trying to get SOMEthing to work.</p>
<p dir="auto">I went into NAT.  No port forwarding.  No 1:1.  Outbound automatic.<br />
I went into Interfaces / WAN.  Clear the checkboxes for blocking private and bogon networks.<br />
I went into Firewall Rules.  The WAN and LAN interfaces each have one rule:  permit everything.</p>
<p dir="auto">By using packet capture on pfsense I monitor traffic while I do this:<br />
Using a 192.168.x.x client, I set static route to the 10.x.x.x network via the pfsense box.  I ping a 10.x.x.x client.<br />
In the packet capture, I see the ICMP Echo Request come in the LAN interface.  I see the Echo Request go out the WAN interface, successfully NAT'd to the 10.x.x.x IP address of pfsense.  I see the Echo Reply come back.  But the Echo Reply does not go to the 192.168.x.x network.  It seems pfsense NAT is forgetting about the connection, or firewall blocking.</p>
<p dir="auto">I go to System Logs / Firewall.  (Clear the log, repeat the above tests).  Nothing new appearing in the log.</p>
]]></description><link>https://forum.netgate.com/topic/54436/1-1-nat</link><generator>RSS for Node</generator><lastBuildDate>Tue, 09 Jun 2026 20:57:32 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/54436.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 Mar 2013 17:06:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 1:1 NAT on Thu, 21 Mar 2013 17:18:13 GMT]]></title><description><![CDATA[<p dir="auto">Not sure what changed.  I just ran through the Setup Wizard, entering all the same stuff that was already there.  And then it started working.  Maybe it just needed a reboot?</p>
]]></description><link>https://forum.netgate.com/post/385768</link><guid isPermaLink="true">https://forum.netgate.com/post/385768</guid><dc:creator><![CDATA[rahvee]]></dc:creator><pubDate>Thu, 21 Mar 2013 17:18:13 GMT</pubDate></item></channel></rss>