OPNsense Forum

English Forums => Tutorials and FAQs => Topic started by: rdy on July 03, 2023, 09:20:09 PM

Title: VLAN to VLAN SNAT
Post by: rdy on July 03, 2023, 09:20:09 PM
Hello,

I am coming from a Sophos UTM and I was able to change my source IP when connecting from one PC in my network to another on a different VLAN.

Basically it was like this,

PC (192.168.10.8.) to VM (192.168.70.20) but changing my source IP to 192.168.70.20 so that VM would see think the traffic was coming from 192.168.70.254 when going to 192.168.70.20.

If it helps, on a WatchGuard I believe it was called a dynamic NAT.

If someone knows how to do this, I would be very grateful.

Cheers,
Rdy.
Title: Re: VLAN to VLAN SNAT
Post by: Bob.Dig on July 04, 2023, 11:45:15 AM
Pls explain, why do you want that odd  behavior.
Title: Re: VLAN to VLAN SNAT
Post by: rdy on July 04, 2023, 11:56:53 AM
I cannot easily change the network settings on the docker instances, and they only allow traffic from the same subnet.

I wouldn't consider it odd behavior, every firewall I have used before Opnsense, it has been something you could do. Though they were enterprise FW's and I have hit the home license limit on the Sophos UTM I was previously using.

So far though I am enjoying Opnsense so it would be upsetting if it can't do this.
Title: Re: VLAN to VLAN SNAT
Post by: Bob.Dig on July 04, 2023, 12:20:01 PM
Quote from: rdy on July 03, 2023, 09:20:09 PM
PC (192.168.10.8.) to VM (192.168.70.20) but changing my source IP to 192.168.70.20 so
You wouldn't change it to the destination PC but to the OPNSense interface I think. You can create such a mapping where you configure outbound NAT.
Title: Re: VLAN to VLAN SNAT
Post by: rdy on July 04, 2023, 12:27:07 PM
Could you please give me an example or instructions? I am not quite sure how to do that sorry.
Title: Re: VLAN to VLAN SNAT
Post by: rdy on July 04, 2023, 12:47:06 PM
Please disregard I have worked it out :).
Title: Re: VLAN to VLAN SNAT
Post by: sorano on July 04, 2023, 04:29:11 PM
Quote from: rdy on July 04, 2023, 12:47:06 PM
Please disregard I have worked it out :).

Damn.... Posts like these always piss me off.

First begging help from others.

Then when you solve whatever problem you had instead of posting the actual solution so others with the same issue could benefit from it they just post "I have worked it out :)" 

FFS ::) ::) ::) ::) ::)