<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Complicated NAT Question]]></title><description><![CDATA[<p dir="auto">Greetings,</p>
<p dir="auto">I am using 2.2.6 pfSense as my router/firewall.  I have two static IPs, which for the purposes of the question we'll say are 1.1.1.1 and 1.1.1.2.</p>
<p dir="auto">I want 99.9% of my network traffic to go out to the Internet as 1.1.1.1, but I would also like to NAT any and all traffic for my web server for 1.1.1.2.  I have a very heavy Cisco background, both in routers &amp; firewalls, and I think it is proving more of a hindrance than a help in this situation.</p>
<p dir="auto">Can anyone please point me to some documentation about how to create this functionality in pfSense?  My searches seems to have turned up conflicting or unclear information.</p>
<p dir="auto">My thanks!</p>
]]></description><link>https://forum.netgate.com/topic/95271/complicated-nat-question</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 19:14:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/95271.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 09 Feb 2016 18:49:32 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Complicated NAT Question on Thu, 11 Feb 2016 11:02:10 GMT]]></title><description><![CDATA[<p dir="auto">No you do not need to remove the auto..  You need to make sure that the webserver talks back out the same IP it came in.</p>
]]></description><link>https://forum.netgate.com/post/601955</link><guid isPermaLink="true">https://forum.netgate.com/post/601955</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 11 Feb 2016 11:02:10 GMT</pubDate></item><item><title><![CDATA[Reply to Complicated NAT Question on Thu, 11 Feb 2016 07:47:05 GMT]]></title><description><![CDATA[<p dir="auto">Yes.  The IPs are both on the same connection.</p>
<p dir="auto">Thanks for your reply.</p>
<p dir="auto">Just to be sure I understand, I will:</p>
<p dir="auto">1. Create appropriate NAT and Firewall rules for Incoming from Virtual IP that point the the web server.<br />
2. Create an outbound NAT rule for my web server to use the Virtual IP.</p>
<p dir="auto">One other question:  Do I need to remove the auto-generated outbound NAT rules, or will my manual outbound NAT rule be prioritized over them?</p>
<p dir="auto">Once again, my thanks!</p>
]]></description><link>https://forum.netgate.com/post/601916</link><guid isPermaLink="true">https://forum.netgate.com/post/601916</guid><dc:creator><![CDATA[Kirloth]]></dc:creator><pubDate>Thu, 11 Feb 2016 07:47:05 GMT</pubDate></item><item><title><![CDATA[Reply to Complicated NAT Question on Tue, 09 Feb 2016 20:10:46 GMT]]></title><description><![CDATA[<p dir="auto">Are these public IPs on different connections or the same one.  So your wan on pfsense as 1.1.1.1, create a vip for 1.1.1.2 and forward traffic to your webserver via your vip.  And then on your outbound nat setup your webserver to use the vip for its outbound traffic.</p>
]]></description><link>https://forum.netgate.com/post/601611</link><guid isPermaLink="true">https://forum.netgate.com/post/601611</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 09 Feb 2016 20:10:46 GMT</pubDate></item></channel></rss>