<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Do I need static routing in this scenario?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I have a pfsense box with 4 nics, WAN, LAN1 (192.168.1.1), LAN2 (192.168.2.1) and CommonLan (192.168.3.1).</p>
<p dir="auto">Internet works fine on all interfaces and this is not the issue here ;-)</p>
<p dir="auto">CommonNet hosts our intranet and ftp server and this subnet should be reachable from both LAN1 and LAN2 on port 20/21 and 80.  However I don't want LAN1 and LAN2 to be able to talk to each other, they should only be able to reach the CommonNet subnet.</p>
<p dir="auto">On the 'Static routes' page, this note is written: "Do not enter static routes on any interface assigned of this firewall…"</p>
<p dir="auto">Does this mean that I don't need static routes in my case? -- and in order to achieve the above goal I just need to write firewall rules for LAN1 and LAN2 with destination CommonNet for the above port numbers?</p>
<p dir="auto">Please advice ;-)</p>
<p dir="auto">Tor</p>
]]></description><link>https://forum.netgate.com/topic/6848/do-i-need-static-routing-in-this-scenario</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 02:44:51 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/6848.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 27 Dec 2007 09:07:36 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Do I need static routing in this scenario? on Wed, 09 Jan 2008 17:17:52 GMT]]></title><description><![CDATA[<p dir="auto">Why dont you just try it?<br />
If it's not working i'm sure someone might help you.</p>
<p dir="auto">Yes. If you want to reach another subnet behind a router on NIC2 then yes you need to add a static route.</p>
]]></description><link>https://forum.netgate.com/post/164378</link><guid isPermaLink="true">https://forum.netgate.com/post/164378</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Wed, 09 Jan 2008 17:17:52 GMT</pubDate></item><item><title><![CDATA[Reply to Do I need static routing in this scenario? on Tue, 08 Jan 2008 22:21:32 GMT]]></title><description><![CDATA[<p dir="auto">Hi folks,</p>
<p dir="auto">I would be <em>very</em> grateful if someone could help me out with the above question, I understand that it might me off-topic, but this is the only issue left before our pfsense works just as needed…</p>
<p dir="auto">regards  Tor</p>
]]></description><link>https://forum.netgate.com/post/164334</link><guid isPermaLink="true">https://forum.netgate.com/post/164334</guid><dc:creator><![CDATA[bushtor]]></dc:creator><pubDate>Tue, 08 Jan 2008 22:21:32 GMT</pubDate></item><item><title><![CDATA[Reply to Do I need static routing in this scenario? on Wed, 09 Jan 2008 07:29:33 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for the useful info</p>
<p dir="auto">Now say that I have three lan nics (in addition to wan).  Nic1 at 192.168.10.1, Nic2 at 192.168.15.1 and Nic3 at 192.168.20.1, both Nic1 and Nic3 with default rules as of wan access (Internet works ok)..</p>
<p dir="auto">In addition, any traffic from either Nic1 or Nic3 to subnet 192.168.30.0/24 should be routed via Nic2.  Nic2 is connected to another router with ip 192.168.15.254.  (Another port on that other router is connected to the 192.168.30.0/24 subnet which Ni1 and Nic3 need to communicate with).</p>
<p dir="auto">Do I use static routes or nat in this case?  Traffic to the 192.168.30.0/24 subnet from workstations connected to Nic1 and Nic3 should be routed via 192.168.20.254 to find the 192.168.30.0/24 net.</p>
<p dir="auto">Thanks a lot if someone can comment on this</p>
<p dir="auto">Tor</p>
]]></description><link>https://forum.netgate.com/post/164290</link><guid isPermaLink="true">https://forum.netgate.com/post/164290</guid><dc:creator><![CDATA[bushtor]]></dc:creator><pubDate>Wed, 09 Jan 2008 07:29:33 GMT</pubDate></item><item><title><![CDATA[Reply to Do I need static routing in this scenario? on Thu, 03 Jan 2008 13:58:46 GMT]]></title><description><![CDATA[<p dir="auto">Let me try to explain how you should see the "flow of traffic".<br />
What you control with rules are what to do with the traffic coming from the cable to the nic.</p>
<p dir="auto">Pc–&gt;--cable---&gt;---nic---&gt;---pfsense rule----&gt;--nic2---&gt;--cable2--&gt;--pc2</p>
<p dir="auto">So if you place the default lan rule on nic every bits and bytes will hit pc2 so to speak. To do it so makes sense in the case that we have the internet and seldom know where to go.</p>
<blockquote>
<p dir="auto">OK, but isn't everything blocked by default?</p>
</blockquote>
<p dir="auto">Yes it is…If you have no rules on nic the traffic form pc can't go anywhere....</p>
<p dir="auto">hope it helps :)</p>
]]></description><link>https://forum.netgate.com/post/164112</link><guid isPermaLink="true">https://forum.netgate.com/post/164112</guid><dc:creator><![CDATA[Perry]]></dc:creator><pubDate>Thu, 03 Jan 2008 13:58:46 GMT</pubDate></item><item><title><![CDATA[Reply to Do I need static routing in this scenario? on Thu, 03 Jan 2008 07:13:20 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/perry">@<bdi>Perry</bdi></a>:</p>
<blockquote>
<p dir="auto">Block rule Source=Lan1 net destination=Lan2 net</p>
</blockquote>
<p dir="auto">OK, but isn't everything blocked by default?</p>
<p dir="auto">I thought I just had to write access rules, say, to allow only http and ftp requests from LAN1 and LAN2 clients to CommonNet:</p>
<p dir="auto">Interface LAN1: Source=LAN1 Dest=CommonNet SourcePort=20,21,80<br />
Interface LAN2: Source=LAN2 Dest=CommonNet SourcePort=20,21,80</p>
<p dir="auto">Comments, please ;-)</p>
<p dir="auto">rgds</p>
<p dir="auto">Tor</p>
]]></description><link>https://forum.netgate.com/post/164102</link><guid isPermaLink="true">https://forum.netgate.com/post/164102</guid><dc:creator><![CDATA[bushtor]]></dc:creator><pubDate>Thu, 03 Jan 2008 07:13:20 GMT</pubDate></item><item><title><![CDATA[Reply to Do I need static routing in this scenario? on Thu, 27 Dec 2007 10:09:18 GMT]]></title><description><![CDATA[<p dir="auto">Yes you don't need static routing, just add a block rule on top of the default lan rule</p>
<p dir="auto">Block rule Source=Lan1 net destination=Lan2 net</p>
]]></description><link>https://forum.netgate.com/post/163812</link><guid isPermaLink="true">https://forum.netgate.com/post/163812</guid><dc:creator><![CDATA[Perry]]></dc:creator><pubDate>Thu, 27 Dec 2007 10:09:18 GMT</pubDate></item></channel></rss>