<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Policy route internal host to external proxy?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I have an internal host which I need to route out through an external proxy.  Unfortunately the device doesn't support a proxy configuration directly, so I need to force this in the network.  How, generally, would I go about setting this up in pfsense?</p>
<p dir="auto">My firewall is super-simple.  one WAN and one LAN interface.  Nothing complicated in the rules.  Block most inbound, allow most outbound.  NAT the internal network behind the WAN IP.  Running 2.1-Release.</p>
<p dir="auto">So far I have done this, and it neither works nor really seems like I'm going about it in the right way:</p>
<ol>
<li>
<p dir="auto">created two routes under System: Gateways for 0.0.0.0/1 and 128.0.0.0/1 (I don't see a way to create a route for 0/0) to the external proxy IP</p>
</li>
<li>
<p dir="auto">in doing step 1, selected the "or add a new one" link to create a GW with the external proxy IP (I cannot go back and edit this, though; the system complains that the IP is not local to any interface)</p>
</li>
<li>
<p dir="auto">created a firewall rule on the LAN interface with a source of the host in question, * port, * destination, * port, and the GW created in step 2 as the gateway.  I am not using queues, so that's set to none.</p>
</li>
</ol>
<p dir="auto">So the traffic isn't routing out to the proxy, and the logs there reflect that.</p>
<p dir="auto">In pfsense the firewall logs for the rule created in step 3 show the real destination for the traffic, not the proxy (I don't know if that's intentional or not).  Also under Diagnostics: Routes I don't have an entry for the routes I configured.</p>
<p dir="auto">Maybe I'm way off base, I appreciate any guidance.</p>
]]></description><link>https://forum.netgate.com/topic/67748/policy-route-internal-host-to-external-proxy</link><generator>RSS for Node</generator><lastBuildDate>Thu, 18 Jun 2026 07:53:42 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/67748.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 10 Apr 2014 01:27:17 GMT</pubDate><ttl>60</ttl></channel></rss>