Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN Gateway IP is not from WAN IP scope

    NAT
    2
    4
    1.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      alftech
      last edited by

      Hi,

      a have one problem.

      ISP provider sets for me new ip address and gateway address, but GW is not from wan IP scope.

      –--------------------------------------------------------
      (not really ip adresses)

      WAN IP : 45.14.15.16/32 (one public ip)
      GW      : 172.16.6.17 Microtik in provider network
      DNS    : some xxx.xxx.xxx.xxx for this time not important.

      when I set this IP to wan interface nat does not work and i can't ping to gateway.
      If I set IP as virtual and 1:1 nat to some computer in my LAN everything works fine.

      Model with 1:1 NAT looks like this example working fine

      WAN IP : 172.16.6.18/29
      GW      : 172.16.6.17
      DNS    : some xxx.xxx.xxx.xxx for this time not important.
      VIRTUAL WAN IP 45.14.15.16 + NAT (1:1) 45.14.15.16/32 to some 192.168.2.x and fireewall rules

      is it possible to set pfsense router to work with wan IP address and gw from other address scope?

      1 Reply Last reply Reply Quote 0
      • Cry HavokC
        Cry Havok
        last edited by

        No device can route if the default gateway is not on a directly connected network.  However, was your netmask specified by your ISP as 255.255.255.255?

        1 Reply Last reply Reply Quote 0
        • A
          alftech
          last edited by

          Yes 32 = 255.255.255.255
          he said thet solve some address scope perhaps 8 + gateway.

          Thank you for your answer.

          1 Reply Last reply Reply Quote 0
          • Cry HavokC
            Cry Havok
            last edited by

            Often people use /32 to refer to a single IP, regardless of the netmask given by their provider, hence my checking ;)

            That arrangement is, to put it mildly, a kludge.  It relies on the OS doing a broadcast for all communications, which not all will do.  I've seen it sometimes set with the host's IP as the gateway and had that work (different OS), but YMMV.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.