OPNsense Forum

English Forums => High availability => Topic started by: andrema2 on July 30, 2021, 02:50:17 PM

Title: CARP WAN interface with double NAT
Post by: andrema2 on July 30, 2021, 02:50:17 PM
Hi All

I have to leave with a double NAT. My ISP doesn't give me a IP on my FW, but theirs.

So my WAN interfaces are a 192.168.15.0/24. I do want to block any traffic coming from this private networks, but allow the CARP communications happen at the same time.

What kind rule should I have at the WAN FW to allow it ? I tried to create two rules one in and another out allowing WAN net to use CARP to the this FW. It didn't work.

How can I make it work ?

Thanks
Title: Re: CARP WAN interface with double NAT
Post by: mimugmail on July 30, 2021, 02:54:38 PM
When you add a CARP interface in floating autogenerated rules it's already allowed