Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Help with Double NAT'ing

    Routing and Multi WAN
    2
    4
    1248
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      deaney last edited by

      Hi Guys,

      This one is driving me crazy.

      Im trying to have my PFsense VM setup so that my VM's are not on the local lan, they all talk through PFsesne and that handles DNS, DHCP etc… effectively acting as a modem/router inside of my virtual network.

      I only want the one IP on my 192.168.1.0 Subnet from the PFsense machine, I want the VM's to pass all traffic through it.

      I have linked the physcial Nic into the PFsesne VM, it goes out to the gateway.

      I edited the rules but still... none of the VM's on the 172 internal network get any internet access..

      Here are some screenshots.

      Thanks in advance!







      ![2013-05-05 2.jpg](/public/imported_attachments/1/2013-05-05 2.jpg)
      ![2013-05-05 2.jpg_thumb](/public/imported_attachments/1/2013-05-05 2.jpg_thumb)
      ![2013-05-05 23_06_34-se.jpg](/public/imported_attachments/1/2013-05-05 23_06_34-se.jpg)
      ![2013-05-05 23_06_34-se.jpg_thumb](/public/imported_attachments/1/2013-05-05 23_06_34-se.jpg_thumb)
      ![2013-05-05 23_06_56-server .jpg](/public/imported_attachments/1/2013-05-05 23_06_56-server .jpg)
      ![2013-05-05 23_06_56-server .jpg_thumb](/public/imported_attachments/1/2013-05-05 23_06_56-server .jpg_thumb)

      1 Reply Last reply Reply Quote 0
      • P
        podilarius last edited by

        For WAN options, do you have it set to block private networks?

        1 Reply Last reply Reply Quote 0
        • D
          deaney last edited by

          Hi podilarius,

          Thanks for the reply - no, its left unticked as I knew this would cause issues due to the IP.

          1 Reply Last reply Reply Quote 0
          • P
            podilarius last edited by

            NP. Just starting with the basics.
            I would ditch the 1:1 rule for now. That is not doing what you think it is. The AON (automatic outbound NAT) is mapping it to only 1 IP address, the WAN address.
            Looks like you will need to port forward anything else internally.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post