Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
CARP/VIPs
»
"Manual outbout NAT rule generation" rule question
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: "Manual outbout NAT rule generation" rule question (Read 606 times)
0 Members and 1 Guest are viewing this topic.
ace
Jr. Member
Offline
Posts: 28
"Manual outbout NAT rule generation" rule question
«
on:
June 25, 2012, 03:29:06 am »
We have 4 interfaces on the pfsense boxes:
1) WAN
2) LAN
3) STAGE LAN
4) XOVER (pfsync).
When we select the radio buttong for "Manual outbout NAT rule generation" it only generates a rule for the WAN with the source being the LAN network.
Interface Source Source Port Destination Destination Port NAT Address NAT Port Static Port
WAN 10.9.32.0/24 * * * * * NO
Sureley the source should be "*", or at least both the the LAN network and the STAGE LAN network (and all network underneath these two - in a muti tier network architecture, the top LAN tier being the DMZ, and APP/DB teirs firewalled underneath it).
Also, surely the default rule should have had the NAT address set to the WAN IP? Obviosly, it needs to be changed to the CARPed WAN ip.
Logged
SeventhSon
Full Member
Offline
Posts: 270
Re: "Manual outbout NAT rule generation" rule question
«
Reply #1 on:
August 17, 2012, 02:17:12 pm »
The standard wouldn't have the NAT set because of PRB/LB I would say. And you wouldn't want it to generate a NAT rule for a LAN interface, that would be weird...
I think once you start with multiple LAN/WAN you would have to go the manual way and put the subnets in yourself. Otherwise, we need an option on each interface to tell us if it's WAN or LAN.
Logged
podilarius
Hero Member
Online
Posts: 1580
Re: "Manual outbout NAT rule generation" rule question
«
Reply #2 on:
August 17, 2012, 04:52:21 pm »
In 2.0.1 and 2.1, if you have interfaces setup with a manual address, then pfsense will create a manual rule for them when switching from auto, the first time you do it. From then on you have to create your own rules.
If you are running clustered firewalls, then you most definitely want it using the CARP addresses. Nothing should be using the physical address except for the localhost (127.0.0.1).
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...