Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Connecting with external IP to servers in DMZ

    Scheduled Pinned Locked Moved NAT
    7 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      Hiki
      last edited by

      Hi

      I am redoing the firewall at a school and i cant access the ftp server in the DMZ from the internal network using its external ip. Using the internal ip works fine, so does connecting from outside. There will be a dns, www and another ftp server in the DMZ later on.

      Nice "ASCII art":

      WAN (192.123.234.224/28)
      |
      |
      PFsense –- DMZ (192.168.2.0/24)
      |
      |
      LAN with several subnets

      Current config is 1:1 nat to the ftp server and wan rules to accept ftp ports and a passive port range to the ftp server. Lan network to everywhere and DMZ to everywhere but the lan network. Ftp helper is also disable on wan and DMZ.

      Hope someone has a solution for this :).

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        http://forum.pfsense.org/index.php/topic,7001.0.html

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • H
          Hiki
          last edited by

          @GruensFroeschli:

          http://forum.pfsense.org/index.php/topic,7001.0.html

          So basically i need to forward ports and turn on nat reflection? Or did i get it wrong?

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            I don't think natreflection will work for ftp but I haven't tried it yet. I would try to use split dns to resolve the internal dmz IP to the lan clients.

            1 Reply Last reply Reply Quote 0
            • GruensFroeschliG
              GruensFroeschli
              last edited by

              I just asked a friend that runs an ftp behind pfSense.

              He's not using the ftp-helper.
              He just forwards port 21 and a range he defined on his server.

              With this kind of setup he can use reflection on his ftp server.

              We do what we must, because we can.

              Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

              1 Reply Last reply Reply Quote 0
              • H
                hoba
                last edited by

                Yes, without the helper it should work.

                1 Reply Last reply Reply Quote 0
                • H
                  Hiki
                  last edited by

                  Turned off ftp-helper on all interfaces and added a port forward on the lan inteface for ftp port and a passive range and it works great :), thx.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.