Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Web server behind virtual IP on WAN

    Scheduled Pinned Locked Moved NAT
    13 Posts 2 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GruensFroeschliG
      GruensFroeschli
      last edited by

      Reread the thread this here is split from.
      also:
      http://forum.pfsense.org/index.php/topic,7001.0.html
      and the wiki: http://doc.pfsense.org/index.php/Main_Page

      You're rules are all wrong.

      WAN: dont allow anyting inbound on port 80.
      Allow as destination only your server.

      LAN: Your second rule doesnt make any sense. Rules are applies on the interface on which traffic is inbound. –> The rule has to go to the WAN tab.
      set as source "any" and not the VIP.

      NAT: you didnt post any NAT rules, so i suppose you didnt create them.
      Create a rule forwarding port 80 with as "external IP" your VIP.

      We do what we must, because we can.

      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

      1 Reply Last reply Reply Quote 0
      • G
        Grogi
        last edited by

        Obviously it won't go easy as I thought….

        I have tried tons of solutions across the web so excuse me if I mess something and sure I was.

        See attachments and we can discuss futher.

        Thanks

        port-fwd.JPG
        port-fwd.JPG_thumb
        ![lan rules.JPG](/public/imported_attachments/1/lan rules.JPG)
        ![lan rules.JPG_thumb](/public/imported_attachments/1/lan rules.JPG_thumb)
        ![wan rules.JPG](/public/imported_attachments/1/wan rules.JPG)
        ![wan rules.JPG_thumb](/public/imported_attachments/1/wan rules.JPG_thumb)

        1 Reply Last reply Reply Quote 0
        • G
          Grogi
          last edited by

          Just to clarify…
          -.-.-.117 is VIP (proxy arp of WAN)
          -.-.-.116 is WAN address
          10.10.0.0/19 is LAN
          Also, there is opt1 but it is irelevant for this.

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            The screenshots look good.

            What does not work?

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • G
              Grogi
              last edited by

              I can not access web page over http://-.-.-.117 which is located on 10.10.25.11

              States:
              tcp 10.10.25.11:80 <- -.-.-.117:80 <- -.-..234:2990 CLOSED:SYN_SENT
              tcp -.-.-.-.234:2990 -> 10.10.25.11:80 SYN_SENT:CLOSED

              1 Reply Last reply Reply Quote 0
              • GruensFroeschliG
                GruensFroeschli
                last edited by

                Are you trying to access from inside your own network or from the outside?
                From the inside will not work.

                The solution would be to enable NAT reflection, however i'm not sure if NAT reflection is compatible with PARP VIPs.

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • G
                  Grogi
                  last edited by

                  I can access localy http://10.10.25.11 or over public 117 in LAN (I enabled NAT reflection and I can open page inside LAN but outside…)

                  1 Reply Last reply Reply Quote 0
                  • G
                    Grogi
                    last edited by

                    The -.-.-.-.234:2990 is machine I controll remotely and try outside network.

                    1 Reply Last reply Reply Quote 0
                    • G
                      Grogi
                      last edited by

                      It seems like everything is ko but it doesn't work. I have tried to give the web server public IP and it is reachable from outside. It is high risk for me and I can't figure out how to do this simple port fwd.

                      Do I have to make any changes on server ie to put gateway which is VIP, i don;t know or to setup some outgoing NAT.

                      Thanks in advance.

                      1 Reply Last reply Reply Quote 0
                      • G
                        Grogi
                        last edited by

                        THe firewall log is ok, the traffic is passed to web server.

                        1 Reply Last reply Reply Quote 0
                        • G
                          Grogi
                          last edited by

                          It would be helpful if someone can provide me screenshots of his configuration for any service which is behind VIP (or WAN IP).
                          I don't know where is mistake, is it NAT or firewall or pfsense generaly.

                          Thanks

                          1 Reply Last reply Reply Quote 0
                          • G
                            Grogi
                            last edited by

                            Usualy it is something stupid. The firewall on local web server blocked traffic.

                            Everything works like a charm.
                            I fwded SSH and HTTP without any problem.
                            Thanks.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.