Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Route a /24 public subnet to another /24 public subnet

    Scheduled Pinned Locked Moved Routing and Multi WAN
    2 Posts 2 Posters 715 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pciccone
      last edited by

      In the next few weeks we will be doing a massive (physical) migration from one public /24 subnet to another public /24 subnet. We will have to update various settings, DNS, firewall entries, etc over 100 servers and related load balancers and appliances. During this time as we update systems we would like it if the old IP pool can forward (masquerade?) to the new IP pool, all ports, in a one-to-one mapping. For example:

      Source IP: 8.8.8.1 (all ports)
      Target IP 9.9.9.1

      Source IP: 8.8.8.2 (all ports)
      Target IP: 9.9.9.2

      We can leave one of our smaller pfSense boxes at the old location to do this forwarding. I know "port forwarding" and "NAT" but these are for proxying data between a public and a private IP. In this case, we need to masquerade/forward/proxy data from a public to a new public IP. We could also establish a site-to-site OpenVPN tunnel, but I am still not sure how to do this. Is this something easy to accomplish?

      Thanks ahead of time for your help, and spending the time to read this post!

      Phil

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        It can be done, with 1:1 NAT for the subnet, OpenVPN with assigned interfaces and the right set of rules.

        You will need to build a static key OpenVPN tunnel between the sites, assign the interfaces on both ends, and make sure to only have firewall rules on the assigned OpenVPN tab.

        If you happen to be a gold subscriber that is one of the topics I talked about in the "Advanced OpenVPN Concepts" hangout back in September.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.