Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
SNat on Portmap - how do I do this?
« previous
next »
Print
Pages: [
1
]
Author
Topic: SNat on Portmap - how do I do this? (Read 697 times)
tverweij
Jr. Member
Posts: 69
Karma: 1
SNat on Portmap - how do I do this?
«
on:
September 04, 2023, 08:59:01 pm »
I have the following situation:
An Ip (from the internet) connects to the firewall.
IP -> WanIP
This IP is in a specific alias, and therefor a NAT rule is executed, changing it in:
IP -> DestIp
DestIp is located on another server, what means that the traffic is routed through an IPSec tunnel
IP -> IPSecAdapter -> Dest IP
On the other server, I see the traffic coming in:
IPSecAdapter -> DestIP
So far, so good.
But now the way back.
For the destination server, the connection comes from IP, and IP is on the internet.
This means that the routing goes to the WAn op the second server and all replies to IP get lost into the void.
To solve this, I need an Outbound NAT on the same traffic as the PortForward is executed on, changing the traffic flow in:
NATIP -> IPSecAdapter -> Dest IP
But whatever I do, the outbound rule won't execute on the traffic.
I can execute it on the IPSec adapter, but when I do that, no traffic reaches the other server anymore.
How can I solve this?
«
Last Edit: September 04, 2023, 10:21:35 pm by tverweij
»
Logged
tverweij
Jr. Member
Posts: 69
Karma: 1
Re: SNat on Portmap - how do I do this?
«
Reply #1 on:
September 04, 2023, 09:30:03 pm »
To make the question somewhat simpler:
How do I apply a source-nat on a portmapping?
«
Last Edit: September 04, 2023, 10:21:51 pm by tverweij
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
SNat on Portmap - how do I do this?