Double NAT Issue PFsense VPN Service and XBOX (WAN)

0

Superuser community. I wasn't able to get help from the Pfsense community, so I'm trying to ask about this issue here.

I have a Pfsense router and a VPN Service. I'm having issues getting my XBOX ONE out of double nat. What I've tried so far:

  • If I disable VPN service it works fine.
  • If I activate it I was getting DNS Leaks(network was fine). The Xbox was pointing to use WAN and would get my ISP Address but the DNS showed my VPN-specific DNS.
  • If I put the XBOX on the side of the VPN so the Xbox goes through the VPN it is still double nat'd

I'm seeking anyone with experience with VPN+Router setups, specifically with NAT configurations.

comet424

Posted 2019-02-07T19:25:15.187

Reputation: 1

Welcome to Super User.  It would appear that you have accidentally created two accounts.  This will interfere with commenting, editing your own posts, and accepting an answer.  You should use the contact form and select “I need to merge user profiles” to have your accounts merged.  In order to merge them, you will need to provide links to the two accounts.  For your information, these are https://superuser.com/users/995494/comet424 and https://superuser.com/users/996020/comet424.%E2%80%82 You’ll then be able to [edit] your question. … … … … … P.S. Please register your merged account.

– Scott – 2019-02-09T03:13:22.873

Answers

0

I don't know why you think you have a double nat problem...you clearly stated you have a DNS problem. Maybe I am misunderstanding?

The DNS service used in your setup would be chosen by pfsense. The XBOX will point to pfsense for DNS, and pfsense will pick one of the services it learned on one of the WAN ports for DNS forwarding. You can manually configure which DNS server to use, but this changes the DNS forwarder settings globally (all devices, all networks). What you probably want to do is edit your DHCP information for your non-vpn network so that devices will contact your ISP DNS instead of pfsense. The XBOX will go directly to your WAN DNS and not ask pfsense for DNS service.

Andy

Posted 2019-02-07T19:25:15.187

Reputation: 1 400