Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Public IP for IP-based Virtual Hosting on DMZ

    HA/CARP/VIPs
    4
    4
    3.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bmcandrews
      last edited by

      I have installed a carp fail over setup which is working fine involving WAN (1 public IP subnet), LAN, SYNC, and 2 DMZs. On the DMZs, I have multiple web servers running IP-based virtual hosting. I have an additional public IP subnet of 64 addresses routed to my WAN address. The servers have a private address and several public alias addresses.

      I have been reading about VIPs and 1:1 and am unsure (and have been unsuccessful in testing) whether I can accomplish what I need to accomplish which is to have a packet from the secondary public range arrive at the WAN port and be routed through to the DMZ server retaining the public address.

      x.x.149.65 pkt <–> /x.x.137.1 WAN <pfsense>192.168.2.1 DMZ/ <--> /x.x.149.65 web host/

      I have tried multiple combinations of VIP, static routes, and 1:1 and so far have been unsuccessful.

      Thank-you in advance.</pfsense>

      1 Reply Last reply Reply Quote 0
      • H
        hexa
        last edited by

        This is not possible. I wanted to do this for ages. :-) Someone please correct me, i wish i'm mistaken.
        I'm still using Linux and proxy arp for my server pool with WAN addresses.

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG
          GruensFroeschli
          last edited by

          I'm not sure if i understand you correctly:

          A public /26 subnet gets routed to your WAN.
          You have a public IP on your servers.

          And what exactly do you want to do?
          Move the public IP's to the pfSense and have private IP's on the Servers? (This is possible)
          But… what for?

          Could you draw a diagram of what you have where (including IP's) and what should go where?

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • dotdashD
            dotdash
            last edited by

            CARPDEV is what is really needed for this, but it's still not working well. Depending on your setup, you may be able to use Other VIPs. See this thread: http://forum.pfsense.org/index.php/topic,7039.0.html
            You could also try adding alias IP's http://doc.pfsense.org/multiple-subnets-one-interface-pfsense.pdf and then adding CARP IPs.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.