• Route from prefix dns name

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    J

    @Gloom:

    Exchange 2003 or 2010? Two different beasts and need a slightly different approach. Also is it only the OWA you are trying to access or are you trying to run the outlook client in RPC over HTTP mode.

    Just to use the EWS API with our own software. Solution: place exchange IP in squid proxy "bypass proxy for this IP"  box. For some reason "Bypass all private IP"  option has no effect.

  • Access Point Stops responding to ICMP commands at night

    Locked
    11
    0 Votes
    11 Posts
    4k Views
    johnpozJ

    So you mean on pfsense you had a scope of say 192.168.1.100-200 and the APs had static IPs of say 192.168.1.150?

    So some dhcp client would come on get an IP of 192.168.1.150 from pfsense?

    So this could cause issue with pinging the AP ip or accessing its gui interface over http.  But it should of had little to do with other clients connecting to the network in general or even using the AP.  Unless these AP were not actual AP and were say natting, Some other client should of been able to use the wireless or wired network just fine

    The only point of the AP ip in actual AP use would be to access the AP directly for config, it has nothing to do with connectivity in general to the network.

    When you say AP, that normally means a device that bridges traffic from wired network to the wireless.  Its IP is not even used in this conversation between a wireless client and wired network.

  • 0 Votes
    4 Posts
    4k Views
    A

    at the end it was that simple, lol

    http://forum.pfsense.org/index.php/topic,56328.0.html

  • Disable port forward rule from shell

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    No, there isn't an option to do that in an easy way from the console. You could hand-edit the config and issue a filter reload manually but there is a lot to go wrong there so I would not recommend it.

  • Accessing camera that is behind Pfsense firewall and DSL Router

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    D

    I was able to get it to work.  I purchased another DSL router (D-link).  I did not set it up it using bridge, however, I am using the double port forwarding.  It is working well and I really appreciate everyone's input and help.  Thanks and blessings, Steve

  • Squid Reverse Proxy URL rewrite

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    M

    ok.

    but what about redirects http to https?

    i have some local services. they uses 80 port and clean http
    but outside local network i wish to use them with https.

    before i was using TMG, but it is soooo sloooow, so i decided to move to pfsense.
    and this is only one question that i didn't find the answer :(

  • Nut remote access broken - needs nat?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    A

    Hi Gloom,

    :) Thanks

    I guess the problem was that I was mixed up with the fields and that 'localhost' would not be accepted at the 127.0.0.1 address.

    Now it works:

    If: LAN
    Proto: TCP
    Scr. addr/Ports: * / *
    Dest Addr/Ports: 192.168.1.1/3493
    NAT IP/Ports: 127.0.0.1/3493

    Maybe the nut settings page should describe this a bit better.

    Thanks all,

    Alfredo.

  • Help needed with Outbound NAT rule for SMTP

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    J

    The firewall rules are evaluated from top to bottom until one matches. So make sure that this rule is placed above any other possible matches.

  • Cannot access my webserver from outside the LAN

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    J

    My webserver uses a low-powered atom processor and has about 99% down time. I keep it off most of the time. I just use it for testing purposes.

  • Enabling loopback functionalty

    Locked
    15
    0 Votes
    15 Posts
    18k Views
    K

    @Gloom:

    Split DNS gives you direct wire speed access to your internal servers (I'm guessing your internal network is running a minimum 100 Mb links but your WAN connection is 10Mb). Makes trouble shooting connections much easier and causes less load on the firewall(s)
    Reflection is fine for home use or small offices but is not really a goer for anything over a dozen users. I you have an internal DNS server it's just a case of altering your IP from the WAN address to the internal addresses.

    I've no idea how you've got your external DNS setup but all you need to do is give all of them the external WAN IP which is what I assume you have now and let the different port based NATs sort out which server gets it.

    Ah ok, I understand. This is only for a small home setup so I guess I'd be better off to just enable NAT reflection. Thanks!

  • Port forwarding problems

    Locked
    43
    0 Votes
    43 Posts
    13k Views
    K

    @Gloom:

    If it's a fixed public IP then just put the NAT on the public interface and add a rule to allow the traffic through to the internal IP. It's exactly the same as the ones you have already setup just on a different interface.

    Ok, I'll try that. Thanks :)

  • Not sure if NAT or Routing problems, but giving a shot anyway

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    H

    Try to keep it simple by breaking down into small steps:

    Can you ping / trace from pfs to WAn and beyond? If tou can then that side is ok. Can you access outside by IP but not name? If so then DNS issue Need to show routing and firewall rules for LAN / WAN to find out more details
  • Forwarding to another port?

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    C

    ok but if you going to forward 443 you will need to apply a cert to it. Either Self signed or a legit one.

  • Simulating diffrent NAT

    Locked
    1
    0 Votes
    1 Posts
    965 Views
    No one has replied
  • 0 Votes
    3 Posts
    3k Views
    S

    OK thanks, that's answered my question.

  • Simple Nat with multiple IP's not working with TekSavvy

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    P

    I have to assume that you have a WAN rules to poke the necessary port openings as holes in the firewall? Those rules are pointing to .150 on the LAN.
    Are you monitoring tcpdump on the firewall to make sure they are getting to the firewall? That would be where I start.

  • Accessing IIS Website on port 85

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C

    If your hosting websites in IIS. Do some research on IIS Host headers. You will then only need to open up port 80 to your IIS box and the DNS does the rest. You wont need to keep doing xxx:85 or 86 etc etc. Much more clean and professional.

  • Multi Host Alias & NAT

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    N

    Oh my bad.  Read rdr as rdp.  :-[

  • Port Fowarding Troubles, 80 forwards, 8080 doesnt from inside LAN.

    Locked
    13
    0 Votes
    13 Posts
    3k Views
    M

    But create yourself internal domain with a-host to that internal ip.
    host that dns sameplace as your ics.local

    other than that i can't help you.

    try even on host file on your computer to use that projects.icsanalytics.com to internal host.

  • TCP Proxy from LAN to WAN

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.