Hi all,

I'm trying to setup pfsense 1.0.1 in a small /29 bit subnet to fire wall some machines behind it (obviously).

This is how it be:
xxx.xxx.xxx.233 ISP's GW via ADSL bridge

xxx.xxx.xxx.234 pfsense WAN - 192.168.1.254 LAN

xxx.xxx.xxx.235 server1 <-> 192.168.1.235
xxx.xxx.xxx.236 server2 <-> 192.168.1.236
xxx.xxx.xxx.237 server3 <-> 192.168.1.237
xxx.xxx.xxx.238 server4 <-> 192.168.1.238

Now it is my is understanding that I should be able to add the xxx.xxx.xxx.235-238 IP's to the Virtual IP proxy-arp and add a 1:1 NAT for each IP with the above mappings and bam!

But sadly this doesn't seem to be the case. With firewall rules on both LAN and WAN interfaces of any:any to any:any, I cannot ping from an internal machine to the internet nor from the internet to the internal machine.

Looking at the ADSL modem's arp table there are never any other entries apart from the WAN IP xxx.xxx.xxx.234

Any idea what I am doing wrong? Am I right in thinking this is possible?


Best Regards,
Jai

Reply via email to