Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Outbound traffic from WAN couldn't access to web/mail server in NAT of LAN

    Scheduled Pinned Locked Moved NAT
    31 Posts 7 Posters 11.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      maaraujo
      last edited by

      jamesseen,

      I couldn't resolve www.bumiasia.com. How are you testing?.

      Saludos.

      1 Reply Last reply Reply Quote 0
      • J Offline
        jamesseen
        last edited by

        Thank you, maaraujo….

        Unfortunately, at moment I still don't have "authority" to modify any setting on the Server. I have to wait me superior officer to do those setting on server.(add default gateway to pfSense box instead of XYZ firewall)

        I'll let u guys to know the latest update soon....

        1 Reply Last reply Reply Quote 0
        • J Offline
          jamesseen
          last edited by

          Dear GuRUs…. one question, if I set default gateway to pfSense firewall, all of the traffic response would be going to pfSense box which is not suitable. I would like to ask is it possible to implement WAN traffic packet from pfSense box toward web/mail server will reply back to pfSense and WAN trafic packet from XYZ firewall toward web/mail server reply back to XYZ firewall???? Please refer again for the below network diagram.
          For Your Information, XYZ has reverse proxy....

          Thank you so much!!!! ::)

          Outside.jpg
          Outside.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • H Offline
            hoba
            last edited by

            Not really possible. Sorry.

            1 Reply Last reply Reply Quote 0
            • S Offline
              sopont
              last edited by

              Hi, friend,,,,

              1. check your ADSL Router pass all port to pfSense WAN interface.
              2. pfsense ports forward are 80, 143, 25, 110 for web and mail server.
              3.all your server default to pfSense LAN interface.

              good luck..

              1 Reply Last reply Reply Quote 0
              • J Offline
                jamesseen
                last edited by

                @Sopon:

                Hi, friend,,,,

                1. check your ADSL Router pass all port to pfSense WAN interface.
                2. pfsense ports forward are 80, 143, 25, 110 for web and mail server.
                3.all your server default to pfSense LAN interface.

                good luck..

                @hoba:

                Not really possible. Sorry.

                Thank you for your reply….
                Can I set 3 default gateways on my servers toward pfSense firewall boxes?? Please refer below network diagram...

                Outside1.jpg
                Outside1.jpg_thumb

                1 Reply Last reply Reply Quote 0
                • S Offline
                  sopont
                  last edited by

                  i think can set to 3 gateways or more, but it defference VLAN and subnet on your servers and then easy subnet pointing to easy gateway. why not you optimized to single pfsense firewall have 1 wan (default), 2 OPT1, and 1 LAN?, and using balancing feature or policy routing for outgoing, and multi homing for incomming.

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    jamesseen
                    last edited by

                    Dear Gurus, due to the servers behind the pfSense box couldn't set a default gateway to 192.200.9.7, I would like to implement a reverse proxy after pfSense box so that remote users from WAN maybe (hopefully)can access to servers without set a default gateway on those servers. What would you think? Is it possible?? Please refer following network diagram. Thanks!!!

                    Outside5.jpg
                    Outside5.jpg_thumb

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      sopont
                      last edited by

                      i think you can set server default gateway to 192.200.9.7, but i don't know what devices is "reverse proxy ".
                      i see your diagram "reverse proxy ", is basic proxy server with bridge function right?. if yes, can your files server ping 192.200.9.7?. if can, you can set to that. if your server can't ping to 192.200.9.7 please resolve packet filter or routing on your "reverse proxy ".

                      good luck

                      1 Reply Last reply Reply Quote 0
                      • J Offline
                        jamesseen
                        last edited by

                        Unfortunately, those servers behind pfSense Box are not able to set default gateway of 192.200.9.7. Due to this problem, I'm planning implement a Reverse Proxy (Pound) after pfSense box. From my noob understanding, with reverse proxy attached to the network, default gateway(192.200.9.7) is not required to be set on those servers…. am I rite??? ??? ??? Thanks for feedback...!!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.