Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.2 Outbound NAT Issue

    Scheduled Pinned Locked Moved NAT
    2 Posts 2 Posters 667 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NotIT
      last edited by

      Any insight to this would be much appreciated! I have a multi wan setup for failover purposes using a gateway group. This has worked fine for months. My 2.1 Outbound NAT rules no longer work in 2.2, my setup is as follows:

      We'll say:
      2.2.2.2-7 WAN 1 Public IPs
      3.3.3.3-7 WAN 2 Public IPs
      192.168.0.x LAN

      In 2.1, I had all LAN outbound traffic going out the gateway group (WAN 1 first), with a manual outbound NAT to 2.2.2.2. However, I have a few servers that need to appear as WAN 2 to the world, so created manual outbound rules for each server. 192.168.0.10 -> 3.3.3.4, 192.168.0.11 -> 3.3.3.5 etc. I created two rules for each server, one for each interface, so any traffic going out either gateway would get NATd to the proper IP.

      There are also 1:1 rules for each offending server.

      This worked for many many months.

      After 2.2, this setup no longer works - as I am unable to NAT outbound traffic on WAN 1 to a WAN 2 IP. The only way I could get this to work was to create a LAN firewall rule that forces all traffic from an alias group of LAN IPs to go out the WAN 2 gateway. Now the outbound NAT works, and only one NAT rule is required (for WAN2 interface). However, this doesn't give any sort of redundancy for these specific servers.

      Is it not possible anymore to NAT traffic on one interface to an IP on another?

      More info can be provided as needed…

      Thanks in advance!

      -NotIT

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        "as I am unable to NAT outbound traffic on WAN 1 to a WAN 2 IP"

        How would that have ever worked??  Makes no sense that would work.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.