<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Trying to translate external ips to get nat to work right. Help.]]></title><description><![CDATA[<p dir="auto">I have a client where their setup looks like this:</p>
<p dir="auto">Cable modem (2.x.x.x)<br />
|<br />
Voip edge device (10.x.x.x)<br />
|<br />
PFSense showing WAN on 10.x.x.x</p>
<p dir="auto">So when I port forward saying "WAN address" for destination, it's looking for 10.x.x.x instead of 2.x.x.x.</p>
<p dir="auto">Now this voip device has me in a "dmz passthrough" type zone, but isn't passing ip addresses as such. How can I route say if someone wants to connect to our openvpn server, or even just to test it, the webgui for the router itself on port 80?</p>
<p dir="auto">I've tried setting up firewall rules to allow port 80 for dest wan address, single ip address with 2.x.x.x or 10.x.x.x typed in there, and none seem to work.</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/topic/97439/trying-to-translate-external-ips-to-get-nat-to-work-right-help</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Apr 2026 13:16:16 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/97439.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 01 Apr 2016 20:13:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Trying to translate external ips to get nat to work right. Help. on Sat, 02 Apr 2016 15:17:21 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/derelict">@<bdi>Derelict</bdi></a>:</p>
<blockquote>
<p dir="auto">OK, then you need to Packet Capture to make sure the OpenVPN connections are hitting your WAN port then make sure there's a WAN rule passing the traffic.</p>
</blockquote>
<p dir="auto">Well I found out the phone guy reconfigured my pfsense to use dhcp instead of static on the wan, so it wasn't the dmz port. I emailed him and he gave me what is supposedly the dmz port ip. So I assigned that static, and did a packet capture on port 1195 and it captured nothing at all. I guess the ball is in his court now -_-</p>
]]></description><link>https://forum.netgate.com/post/612550</link><guid isPermaLink="true">https://forum.netgate.com/post/612550</guid><dc:creator><![CDATA[elementalwindx]]></dc:creator><pubDate>Sat, 02 Apr 2016 15:17:21 GMT</pubDate></item><item><title><![CDATA[Reply to Trying to translate external ips to get nat to work right. Help. on Sat, 02 Apr 2016 03:47:47 GMT]]></title><description><![CDATA[<p dir="auto">OK, then you need to Packet Capture to make sure the OpenVPN connections are hitting your WAN port then make sure there's a WAN rule passing the traffic.</p>
]]></description><link>https://forum.netgate.com/post/612488</link><guid isPermaLink="true">https://forum.netgate.com/post/612488</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Sat, 02 Apr 2016 03:47:47 GMT</pubDate></item><item><title><![CDATA[Reply to Trying to translate external ips to get nat to work right. Help. on Sat, 02 Apr 2016 01:47:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/derelict">@<bdi>Derelict</bdi></a>:</p>
<blockquote>
<p dir="auto">OK then it should be working if the "DMZ" is in place.  There are lots of other good troubleshooting steps on that link.<br />
<strong>Diagnostics &gt; Packet Capture</strong> WAN on the outside port that should be getting hit and see if the traffic is actually getting there.</p>
<p dir="auto">Post what you've done for the Port Forward and its associated WAN firewall rule.</p>
<p dir="auto">The outside users will have to connect to the 2. address but it will have nothing to do with anything on the pfSense port forward. pfSense's 10. address on its WAN will be the Destination address and the (as yet unspecified) inside host will be the NAT IP.</p>
</blockquote>
<p dir="auto">Since the pfsense itself is hosting the openvpn, it will be what the firewall rule is for. We have no need for port forwarding to anything inside the network.</p>
]]></description><link>https://forum.netgate.com/post/612479</link><guid isPermaLink="true">https://forum.netgate.com/post/612479</guid><dc:creator><![CDATA[elementalwindx]]></dc:creator><pubDate>Sat, 02 Apr 2016 01:47:33 GMT</pubDate></item><item><title><![CDATA[Reply to Trying to translate external ips to get nat to work right. Help. on Fri, 01 Apr 2016 21:43:41 GMT]]></title><description><![CDATA[<p dir="auto">OK then it should be working if the "DMZ" is in place.  There are lots of other good troubleshooting steps on that link.<br />
<strong>Diagnostics &gt; Packet Capture</strong> WAN on the outside port that should be getting hit and see if the traffic is actually getting there.</p>
<p dir="auto">Post what you've done for the Port Forward and its associated WAN firewall rule.</p>
<p dir="auto">The outside users will have to connect to the 2. address but it will have nothing to do with anything on the pfSense port forward. pfSense's 10. address on its WAN will be the Destination address and the (as yet unspecified) inside host will be the NAT IP.</p>
]]></description><link>https://forum.netgate.com/post/612441</link><guid isPermaLink="true">https://forum.netgate.com/post/612441</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Fri, 01 Apr 2016 21:43:41 GMT</pubDate></item><item><title><![CDATA[Reply to Trying to translate external ips to get nat to work right. Help. on Fri, 01 Apr 2016 20:40:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/derelict">@<bdi>Derelict</bdi></a>:</p>
<blockquote>
<p dir="auto">You have to port forward to pfSense from the cable modem.</p>
<p dir="auto">See problem #8 https://doc.pfsense.org/index.php/Port_Forward_Troubleshooting</p>
<p dir="auto">In your case the voip device is not between you and the internet, the cable modem is.  Or maybe both.</p>
</blockquote>
<p dir="auto">What do you mean? The cable modem is in full pass-through to the voip edge device. The voip edge device is putting the pfsense in a dmz zone forwarding all ports except voice related.</p>
]]></description><link>https://forum.netgate.com/post/612433</link><guid isPermaLink="true">https://forum.netgate.com/post/612433</guid><dc:creator><![CDATA[elementalwindx]]></dc:creator><pubDate>Fri, 01 Apr 2016 20:40:16 GMT</pubDate></item><item><title><![CDATA[Reply to Trying to translate external ips to get nat to work right. Help. on Fri, 01 Apr 2016 20:32:33 GMT]]></title><description><![CDATA[<p dir="auto">You have to port forward to pfSense from the cable modem.</p>
<p dir="auto">See problem #8 https://doc.pfsense.org/index.php/Port_Forward_Troubleshooting</p>
<p dir="auto">In your case the voip device is not between you and the internet, the cable modem is.  Or maybe both.</p>
]]></description><link>https://forum.netgate.com/post/612431</link><guid isPermaLink="true">https://forum.netgate.com/post/612431</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Fri, 01 Apr 2016 20:32:33 GMT</pubDate></item></channel></rss>