Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dual WAN manual NAT being blocked by firewall?

    NAT
    3
    6
    1.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Modivion
      last edited by

      Hello Guys,

      I am trying to configure Pfsense in a dual wan mode.
      Currently I have 2 WANs succesfully setup.

      I have created manual rules for outbound nat. Please find the attached screenshots.

      On network 192.168.10.1, I have internet with WAN1, which is perfect.
      On network 192.168.20.1, I don't have any internet. It seems like the firewall is blocking this, see screenshots.

      Anything I'm doing wrong here?

      Thanks!

      Kind regards,

      Roy

      ![Screen Shot 04-15-14 at 11.27 PM 001.PNG](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.27 PM 001.PNG)
      ![Screen Shot 04-15-14 at 11.27 PM 001.PNG_thumb](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.27 PM 001.PNG_thumb)
      ![Screen Shot 04-15-14 at 11.30 PM 001.PNG](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.30 PM 001.PNG)
      ![Screen Shot 04-15-14 at 11.30 PM 001.PNG_thumb](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.30 PM 001.PNG_thumb)
      ![Screen Shot 04-15-14 at 11.30 PM.PNG](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.30 PM.PNG)
      ![Screen Shot 04-15-14 at 11.30 PM.PNG_thumb](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.30 PM.PNG_thumb)
      ![Screen Shot 04-15-14 at 11.31 PM.PNG](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.31 PM.PNG)
      ![Screen Shot 04-15-14 at 11.31 PM.PNG_thumb](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.31 PM.PNG_thumb)

      1 Reply Last reply Reply Quote 0
      • M
        Modivion
        last edited by

        Firewall rules.

        ![Screen Shot 04-15-14 at 11.33 PM.PNG](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.33 PM.PNG)
        ![Screen Shot 04-15-14 at 11.33 PM.PNG_thumb](/public/imported_attachments/1/Screen Shot 04-15-14 at 11.33 PM.PNG_thumb)

        1 Reply Last reply Reply Quote 0
        • V
          viragomann
          last edited by

          Your firewall rule for LAN2 interface allowing outbound is wrong. You have set the source to LAN Net, have to be LAN2 Net!

          1 Reply Last reply Reply Quote 0
          • M
            Modivion
            last edited by

            Thank you, that was a stupid mistake.

            Fixed that, so no more firewall blocks, but still no internet on the second lan.

            Any ideas?

            1 Reply Last reply Reply Quote 0
            • P
              phil.davis
              last edited by

              You need at least 4 Outbound NAT rules:
              On WAN: LANnet to any and LAN2net to any.
              On WAN2: LANnet to any and LAN2net to any.

              By default, both LAN and LAN2 traffic will go out the default gateway (usually WAN). So next you will have to setup gateway group/s and policy-routing rules to direct traffic to the WANs that you want.

              Note: Automatic Outbound NAT should work fine in your configuration - it will NAT both LANs going out both WANs. So I do not understand why you have chosen Manual Outbound NAT??? Go back to Automatic and see if it works.

              As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
              If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

              1 Reply Last reply Reply Quote 0
              • M
                Modivion
                last edited by

                Changed it back to automatic mode and assigned different gateways in the allow all rules for both LAN 1 and LAN 2.

                That fixed it.

                Thanks for the support.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.