OPNsense Forum

Archive => 18.1 Legacy Series => Topic started by: BenKenobi on April 12, 2018, 05:49:52 pm

Title: What does this 'really' mean ...
Post by: BenKenobi on April 12, 2018, 05:49:52 pm
In the latest 'update' notice I see this phrase

"Three mentionable changes are included: We are switching back to single-source NAT on the primary IP instead of using all additional VIPs on the interface. "

This means what to me exactly - since I DO use VIP's (well Alias's) - I have an allocation of IP's and I use 4 of them for NAT onto internal servers - I don't use the 'primary' IP for any of this which I am taking to mean the root IP of the allocation.

If I read this correctly it is 'cannot use VIP for NAT any more' - which is a show stopper for me.
Title: Re: What does this 'really' mean ...
Post by: franco on April 12, 2018, 06:10:56 pm
Hi there,

18.1.6 restores the pre-18.1 automatic outbound NAT behaviour for VIPs: ignore instead of use. This isn't perfectly clear from the notes, I agree..

We've gone through this due to a larger rework and then early 18.1 indicated that this was a suboptimal solution.

A way was found to keep the rework and still limit the automatic outbound NAT usage to non-VIP like it was in 17.7 and earlier.

This shouldn't be a show stopper in any way. :)


Cheers,
Franco
Title: Re: What does this 'really' mean ...
Post by: BenKenobi on April 12, 2018, 06:15:18 pm
Got it - just checking, nothing worse than spending 4 hours rebuilding after not paying heed to such things.

Appreciate the speed of response.
Title: Re: What does this 'really' mean ...
Post by: franco on April 12, 2018, 06:16:18 pm
https://github.com/opnsense/changelog/commit/6d02ad3c3a9

The changelogs were pushed to the mirrors to reflect that correction. It may take a few hours for all mirrors to sync up with this change.


Cheers,
Franco