Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
NAT
»
2 VLANs/2 External IPs - Outbound NAT
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: 2 VLANs/2 External IPs - Outbound NAT (Read 1344 times)
0 Members and 1 Guest are viewing this topic.
nexus_VI
Newbie
Offline
Posts: 5
2 VLANs/2 External IPs - Outbound NAT
«
on:
November 08, 2011, 08:23:36 am »
Hello,
I have an Alix 2d3 box running pfSense, using only 2 of the 3 interfaces (one reserved for WAN2 connection, coming soon) and using VLAN config on the LAN interface:
WAN - external IP xx.yy.zz.123
LAN - disabled
VLAN 10 - 192.168.2.0/24
VLAN 20 - 192.168.0.0/24
WAN2 - disabled
Now I want both LAN subnets to use a seperate WAN address and have specified a Virtual IP of type "IP Alias" on the WAN connection, "xx.yy.zz.124".
I have also enabled Advanced Outbound NAT and defined two rules:
Interface Source Source Port Destination Destination Port NAT Address NAT Port Static Port
WAN 192.168.2.0/24 * * * * * NO
WAN 192.168.0.0/24 * * * xx.yy.zz.124 *
NO
The problem is, this is not working for the 192.168.0.0/24 subnet, which should use the IP Alias as external address, i cannot get an internet connection here. In the 192.168.0.0/24 subnet, everything is working fine. If I define the Translation Address as "Interface Address" (same setting as for 192.168.2.0/24 subnet), everything works fine.
What am I missing here?
«
Last Edit: November 08, 2011, 09:29:58 am by nexus_VI
»
Logged
Metu69salemi
Hero Member
Offline
Posts: 1559
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #1 on:
November 09, 2011, 12:52:19 pm »
By default you have no any passing rules in other interfaces than lan. have you any rules on that interface?
Logged
nexus_VI
Newbie
Offline
Posts: 5
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #2 on:
November 10, 2011, 01:52:23 pm »
Thanks for the reply, I have the same rules on both VLAN interfaces if you mean those, resembling the default "LAN to any" rule. For the first VLAN (192.168.2.0/24) it's working, the difference being that it doesn't have the IP alias as mapping address of course.
Logged
podilarius
Hero Member
Offline
Posts: 1580
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #3 on:
November 10, 2011, 07:25:36 pm »
Is your 124 address setup as a virtual IP? If so what kind?
Logged
nexus_VI
Newbie
Offline
Posts: 5
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #4 on:
November 13, 2011, 03:09:16 pm »
Yes, i chose the type "IP Alias". It doesn't work with Proxy ARP/CARP either though, I remember trying that.
Logged
podilarius
Hero Member
Offline
Posts: 1580
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #5 on:
November 14, 2011, 06:19:09 am »
Could you post your rules and advanced NAT rules?
Logged
N8LBV
Newbie
Offline
Posts: 19
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #6 on:
February 05, 2012, 12:14:01 am »
I'm having the same problem..
Would have been nice if this asshole ever came back and let us know what happened..
This shit pisses me off royally.
Have some decency folks..
Come back and close the damn thread.
Logged
N8LBV
Newbie
Offline
Posts: 19
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #7 on:
February 05, 2012, 12:21:02 am »
I imagine this is answered somewhere else around here..
But I'm having the same (or similar) problem..
I have setup a second subnet on a second lan interface and setup my outbound rules..
It works if set to (INTERFACE) and goes out on the default WAN Interface..
If I set it to virtual IP I have created it won't go out can't reach internet.
My virtual ip *is* up and pingable from outside and I can reach it if I set rules to allow inbound.
But I'm not getting Nat outbound to the virtual IP when I try it..
Works fine if I don't use the virtual IP (choosing just the wan interface) but I need it to nat and go out on the virtual public ip if coming from this second subnet :-(
Again.. thanks I imagine this has already been asnwered.. just all the endless threads where poeple ask for help, get help and never come back to tell us what
happened really sucks.
Steve
«
Last Edit: February 05, 2012, 12:23:06 am by N8LBV
»
Logged
N8LBV
Newbie
Offline
Posts: 19
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #8 on:
February 05, 2012, 12:49:03 am »
Well bloody hell (as they say).
A reboot did it.
resetting state didn't..
Maybe there some other massive network restart commands I should learn.. I seriously didn't think I needed to reboot to get this to go but sure did!
Insanely happy it's working now!!
Logged
podilarius
Hero Member
Offline
Posts: 1580
Re: 2 VLANs/2 External IPs - Outbound NAT
«
Reply #9 on:
February 06, 2012, 10:14:53 pm »
I am glad that you did a reboot and figured this out. Some times if you setup it up one way and then come back and want to setup it up a different way, a reboot is necessary to clear out the old config from memory and then load up the way that works.
This has been covered in other threads. I do understand that some don't come back and explain, but some find the other threads and thing that others will as well. The problem is that they could link what they find and don't So, if you find this in another thread, please link this tread to that one.
Any way ...
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...