OPNsense Forum

Archive => 18.1 Legacy Series => Topic started by: manueljben on July 05, 2018, 03:40:11 pm

Title: Nat 1:1
Post by: manueljben on July 05, 2018, 03:40:11 pm
Hi all,

I've been waiting to upgrade to 18.1 because i suffered many issues in the past with "early updates".
Some days ago i've finally decided to upgrade my opnsense from 17.7 to 18.1.11 (11 seems to be a minor number quite nice where many things are fixed)....

Then after the upgrade... baboom.. everything seems to be working BUT no NAT 1:1.
I have a public ipv4 subclass from my provider, and have some servers in the DMZ, so I have a Nat 1:1 mapping for all of them. Eg:

x.x.x.150 <-> 192.168.10.150

and in virtualip the ip x.x.x.150 is added (proxyarp).  In 17.7 is working perfectly, but in 18.1.11 (in theory is the same config!, i've already restored the config dump many times...) is not.

Any advices that what could be happening?
Thanks in advance
Title: Re: Nat 1:1
Post by: marjohn56 on July 05, 2018, 04:50:49 pm
I use 1:1 NAT for two servers, it works fine, so may be just a little change is required to your system.


In my 1:1 NAT settings I have the following for one of my servers:


(https://preview.ibb.co/bzetrd/Capture.png) (https://ibb.co/iRBjxJ)


I then have the corresponding firewall rules set on the WAN.
Title: Re: Nat 1:1
Post by: manueljben on July 05, 2018, 10:36:46 pm
Hi marjohn,

I have exactly my config like that, and the rules in WAN.  Works in 17.7 but not in 18.1.11 :-(

I've exported the config xml file from 17.7 and 18.1.11 and is the same (with minor differences of minor versions on some tags, but rules and nat 1:1 are exactly the same)...
Title: Re: Nat 1:1
Post by: marjohn56 on July 05, 2018, 11:44:49 pm

Odd.


Here's my WAN firewall rules just for comparison, this is for my mail server, I use Aliases as you can see.


(https://preview.ibb.co/coN6ey/Capture.png) (https://ibb.co/ebOZXJ)


If that's all correct too, then I suggest you delete the rules and 1:1 NAT and re-enter them from scratch. Seem to recall a few people had issues when they changed to 18.1 but I thought that had been resolved long ago.



Title: Re: Nat 1:1
Post by: manueljben on July 06, 2018, 07:49:48 am
I'm sure I'd deleted nat 1:1 and recreated from scratch in one of my many tries to get it working, but not the rules.

Will try. Thanks for your support marjohn!