Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New book: VLANS in pfSense for absolute non-technical noobs

    Scheduled Pinned Locked Moved Routing and Multi WAN
    42 Posts 5 Posters 9.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      Mr. Jingles
      last edited by

      Oh, I forgot: the !lan is a very neat trick that has solved some head pains(!), thank you for mentioning it  :P

      6 and a half billion people know that they are stupid, agressive, lower life forms.

      1 Reply Last reply Reply Quote 0
      • P Offline
        phil.davis
        last edited by

        So, I interpret that a gateway, 'the way to get out of a LAN', does a sort of NAT.

        The gateway on each LAN is just the way out for routing. It does not do any NAT. The routing software in (pfSense/FreeBSD/any router) is happy to route stuff between all the actual subnet addresses that it knows are directly connected. Then it has gateway(s) itself to use to send packets to other IP addresses that it cannot deliver directly.
        For stuff from the internal LANs, that has to be sent out to another router (through a gateway that pfSense knows about - your ISP or…) NAT (a different piece of functionality) is usually needed. That happens on the way OUT to the upstream gateway/router. NAT is only needed if the upstream gateway does not know how to route back to your internal LAN/s - which is always the case when your LAN/s is in private IP space and the upstream gateway/router is your ISP on the public internet.

        are all these functions done by the gateway of the network segment (3.1), or by the 'main' gateway, 2.1?

        Yes, by default these network services are listening on each of your LAN-style interfaces. For DHCP, you enable it on each LAN-style interface. DNS and NTP just listen on every interface when they are enabled. So, a client on the "2" network would use 2.1 as the address for all these services - DHCP, DNS, NTP… and a client on the "3" network uses 3.1 and so on.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.