Netgate SG-1000 microFirewall

Poll

A quick Multi-NAT question?

I have multi nat
2 (66.7%)
no i dont have multi nat
1 (33.3%)

Total Members Voted: 3

Author Topic: A quick Multi-NAT question?  (Read 4977 times)

0 Members and 1 Guest are viewing this topic.

Offline tiptoe

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
A quick Multi-NAT question?
« on: April 21, 2012, 02:23:32 am »
Hi all,

I wanted to drop by and ask if anyone knows how to setup Multi-NAT for example with my current Draytek router i have it setup like this

LAN IP Network Configuration:

For NAT Usage:
   1st IP Address: 192.168.1.1
   1st Subnet Mask: 255.255.255.0   
For IP Routing Usage:
   2nd IP Address: 81.XXX.26.193
   2nd Subnet Mask: 255.255.255.240

What i would like to know is how do i set this up in pfSense? currently my servers have their NIC's setup looking at one of the IP.s from my public subnet range. I am been clicking and trying everything, but for some reason i carnt get the servers to be seen externally. Any help would be greatly appreciated ;-)

Thanks so much.

Offline M.I.Bovrd

  • Jr. Member
  • **
  • Posts: 55
  • Karma: +0/-0
  • M.I.Bovrd
    • View Profile
    • CQRITEŽ
Re: A quick Multi-NAT question?
« Reply #1 on: April 21, 2012, 02:01:24 pm »
This doesn't make much sense to me, need more info. A picture can say a thousand words.

Is the public 81.x.x.x on the WAN interface?
The private 192.x.x.x on the LAN?
Servers on the LAN?

Need a Forward rule for each server's service that you need to make visible on the WAN, Outside.
You may also need a firewall rule to allow it.
By default you have access outbound from the LAN to the WAN, but not inbound.

pfSense documents will tell you how. The book has even more info.
http://doc.pfsense.org/index.php/Main_Page
Tweet: MIBovrd@cqrite http://www.cqrite.com

Offline tiptoe

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Re: A quick Multi-NAT question?
« Reply #2 on: April 22, 2012, 05:52:18 am »
Thats correct, yes

For NAT Usage:
   1st IP Address: 192.168.1.1 << This is the internal subnet (LAN)
   1st Subnet Mask: 255.255.255.0   
For IP Routing Usage:
   2nd IP Address: 81.XXX.26.193 << This is my WAN range
   2nd Subnet Mask: 255.255.255.240

However i have my server NIC cards set to look at the external (Public) subnet range.

Offline tiptoe

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Re: A quick Multi-NAT question?
« Reply #3 on: April 22, 2012, 05:54:35 am »
The only prob with server forwarding i have is that some of my servers have licensed software on them. And when i route it in this way the license servers see the IP from my local (LAN) subnet range and not that of the actually public (WAN) IP, if that makes any sense

Offline stephenw10

  • Administrator
  • Hero Member
  • *****
  • Posts: 12275
  • Karma: +494/-15
    • View Profile
Re: A quick Multi-NAT question?
« Reply #4 on: April 22, 2012, 07:37:56 am »
Do you have more than one public IP? And you want to assign these to your internal servers?

What software is that that won't work on a private IP address?  ::) Are you sure it can't be configured to do so?

Steve
« Last Edit: April 22, 2012, 07:39:38 am by stephenw10 »

Offline tiptoe

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Re: A quick Multi-NAT question?
« Reply #5 on: April 22, 2012, 10:11:08 am »
Thats correct, i have a block of 16 public IP's assigned by my upstream provider.

As for the software licensing issues. I need the external vendors license servers to see the public IP, or it will error when i try and use it. You see most of the web biased software i am using, uses live license server call-backs to their servers to verify the servers license status and IP usage. If it differs to what is on my account, it will display a license error. This is due to the my server broadcasting on a local subnet, rather than my public one. Now my current setup is a Draytek Vigor 2820 router, and that has a double subnet range feature, one being the local and one being public. Now how i have configured my internal servers, is the NIC cards have the public ip i want assigned them, then the public subnet mask and then the public ip of the router it passes. I would like to upgrade to pfsense, but before i can do this i need to be able to sort the issues i have with Multi-NAT with pfSense.
« Last Edit: April 22, 2012, 10:15:31 am by tiptoe »

Offline tiptoe

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Re: A quick Multi-NAT question?
« Reply #6 on: April 23, 2012, 04:45:10 pm »
Does anyone know how this would be done?  :)

Offline stephenw10

  • Administrator
  • Hero Member
  • *****
  • Posts: 12275
  • Karma: +494/-15
    • View Profile
Re: A quick Multi-NAT question?
« Reply #7 on: April 23, 2012, 06:39:20 pm »
The way this is often handled is to add virtual IP's on your wan and then use 1:1 NAT to your internal servers.

Steve

Offline tiptoe

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Re: A quick Multi-NAT question?
« Reply #8 on: April 24, 2012, 11:24:19 am »
But you see that would mean assigning the internal server with a local ip from the local subnet rather than a public ip from the public subnet range wouldnt it?

At this moment in time this is how my traffic is managed

Internet >> 81.XXX.26.193 (Draytek Router) > 81.XXX.26.194 (Web Servers Public IP) > Internal Server (NIC Assigned with public IP, subnet mask and routers public IP

Offline tiptoe

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Re: A quick Multi-NAT question?
« Reply #9 on: April 24, 2012, 11:52:02 am »
This is how i set it up and when i try and get it to go i can surf the internet ok with it but no internal traffic is able to see the internal server on its public ip



So it looks like i have set it up ok, Now as i have fiber (BT Infinity) i have my WAN interface configured as a PPPoE dialer. This is the only way that i can do this as there are no vDSL/FTTC modems yet on the market here in the UK. Well if there is they are megga expensive. So what do i do next to get this working?

Offline stephenw10

  • Administrator
  • Hero Member
  • *****
  • Posts: 12275
  • Karma: +494/-15
    • View Profile
Re: A quick Multi-NAT question?
« Reply #10 on: April 25, 2012, 07:33:56 am »
But you see that would mean assigning the internal server with a local ip from the local subnet rather than a public ip from the public subnet range wouldnt it?

Yes but that shouldn't be a problem because traffic to/from the server externally will appear to be from whatever public IP you have set it to.

1:1 NAT is not meant to work as you have it setup. It is supposed to tranlate public to private IPs. You will not be able to reach your servers as there is no route to reach them.

It's possible to disable NAT altogether and route the public IPs to your server which is what you want to do. However I have no experience with that.  :-\
I would think you could achieve everything you need to using all private IPs internally.

I have BT infinity so I understand your connection setup. You are presumably using the HG612 supplied by BT/Openreach?

Steve
« Last Edit: April 25, 2012, 03:17:19 pm by stephenw10 »

Offline M.I.Bovrd

  • Jr. Member
  • **
  • Posts: 55
  • Karma: +0/-0
  • M.I.Bovrd
    • View Profile
    • CQRITEŽ
Re: A quick Multi-NAT question?
« Reply #11 on: April 25, 2012, 11:45:35 am »
You probably need to bridge the WAN and LAN if your servers inside have to recognize it's own IP. If you need an internal network too then add a add a second interface for it.

I think that most use a second interface OPT1, renamed DMZ or SERVERS etc. as the Bridged interface and the LAN for a NAT internal network. The Book has some info on setting up a bridge, and I am sure there is some info online etc.

There are some routing challenges between the networks in this senario, because you gateway is now your ISP's router and that won't know how to get to your internal LAN network.

If you don't need a second interface then just bridge the WAN and LAN.

Select Interfaces -> Assign: Select 'Bridges' tab and click the + in the grey box to assign the bridge. Select WAN and LAN and away you go. Only click advanced if u know what you are doing.

Hope this helps.
Tweet: MIBovrd@cqrite http://www.cqrite.com