I have created a similar network and this is exactly what I do. Not translating addresses greatly simplifies any DNS configuration where you give names to all of your devices, too.
On 03/30/2018 12:41 PM, Steve Yates wrote: > Wouldn't it be easier to just create a firewall rule to allow the Guest VLAN > to the printer IP:port? It would be the same thing...they can only access > that IP:port? > > -- > > Steve Yates > ITS, Inc. > > -----Original Message----- > From: List <list-boun...@lists.pfsense.org> On Behalf Of Yilmaz Bilgili > Sent: Friday, March 30, 2018 10:33 AM > To: email@example.com > Subject: [pfSense] Nat between vlans > > Dear all, > > I have a multi vlan setup and I want to give access to my printer on > corp vlan from guest vlan. There is no access from guest vlan to corp > vlan at the moment (and will never be). Can I use an IP address from > guest vlan and nat it to printer's IP address on the corp network? My > box is an up to date 2.4.2. > > Thanks in advance. > > Best regards. _______________________________________________ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold