Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VIP Limitations?

    General pfSense Questions
    3
    3
    687
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      grahamhill4
      last edited by

      I'm having trouble with some protocols that rely on the outbound and inbound traffic passing through the same IP Address i.e. outbound through the single WAN port and incoming through a Virtual IP address bound to the single WAN port.

      Is it possible to direct outbound traffic from a specific subnet/OPT interface to a VIP?

      Many Thanks in advance for any clues.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        It should be possible.  I use outbound NAT to have my mail server sending using a specific VIP that is used by my mail appliance.  IN other words, mail appliance receives mail at VIP and then forwards the processed mail to real server.  When you send a mail out through real server, it uses outbound NAT to appear to send the traffic out from the same VIP that my mail appliance is port forwarded to.  In your case, oyu want to use a network instead of a host as the source.

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          Hybrid outbound NAT is probably what you want. You can direct NAT to use any available public address of the proper type as the inside global (mapped) address based on any unmapped characteristics of the traffic (source, dest, etc).

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.