Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Some external hosts can connect through WAN, others can't

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 4 Posters 4.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Cry HavokC
      Cry Havok
      last edited by

      Sounds like a problem outside your LAN.

      Do you run your webmail on port 80/TCP or port 443/TCP?  Doe the locations that people can't connect from have anything in common (ie, are they all places of work, wireless hot-spots, etc)?

      1 Reply Last reply Reply Quote 0
      • S
        Supermule Banned
        last edited by

        If it is LAN users that cannot connect, it is because Pfsense cannot do packet inspection with Layer7 over the same interface….In short, it cannot analyze the packets and send them back to the mailserver.

        You can overcome that, by either using VLAN enabled switch, optional NIC or find Layer7 capable firewall... :)

        1 Reply Last reply Reply Quote 0
        • S
          schnarky42
          last edited by

          @Cry:

          Sounds like a problem outside your LAN.

          Do you run your webmail on port 80/TCP or port 443/TCP?  Doe the locations that people can't connect from have anything in common (ie, are they all places of work, wireless hot-spots, etc)?

          Internally across the LAN, everyone can connect fine. It's outside access that is problematic. Webmail runs across port 443. The places that seem to have problems are people who work from home and use residential DSL/Cable. We have a co-location server and that server can access everything fine. We also have a satellite office that can access everything as well.

          1 Reply Last reply Reply Quote 0
          • S
            schnarky42
            last edited by

            Firewall and NAT settings if this helps any. Disabling the RFC1918 and Bogon rule did not solve the issue either. We also have load balancing with failover on opt1 with cable; could that cause this problem?

            firewallcrop.PNG
            firewallcrop.PNG_thumb
            natcrop.PNG
            natcrop.PNG_thumb

            1 Reply Last reply Reply Quote 0
            • S
              Supermule Banned
              last edited by

              That depends on the external IP and DNS settings for the loadbalancer….

              1 Reply Last reply Reply Quote 0
              • Cry HavokC
                Cry Havok
                last edited by

                Time for a network diagram too I think, you've mentioned important details in a later post that you overlooked at the beginning ;)

                1 Reply Last reply Reply Quote 0
                • S
                  schnarky42
                  last edited by

                  Here's a quick diagram, will this work?

                  T1 - Static IP–----- WAN-----|
                                                            |
                                                              Load balance & Failover --- LAN Subnet
                                                            |
                  Cable - DHCP------- OPT1----

                  1 Reply Last reply Reply Quote 0
                  • Cry HavokC
                    Cry Havok
                    last edited by

                    So:

                    1. Where's your server - on the LAN?
                    2. What connection to people use to connect to the server - T1 or Cable?
                    3. If you run a packet capture on that interface, do you see the packets that don't reach the pfSense host?
                    1 Reply Last reply Reply Quote 0
                    • S
                      schnarky42
                      last edited by

                      @Cry:

                      So:

                      1. Where's your server - on the LAN?
                      2. What connection to people use to connect to the server - T1 or Cable?
                      3. If you run a packet capture on that interface, do you see the packets that don't reach the pfSense host?

                      1.) Yes, all servers are within the LAN, no DMZ. I can detail the network diagram when I have some spare time later today.
                      2.) From the outside, people connect to the server via the T1. I setup the NAT and firewall rules accordingly (see the NAT/Firewall images in my previous post)
                      3.) I'll have to switch back in PFsense and run capture over the weekend, as of right now our Pix is in and using the T1.

                      Thanks for your help so far Cry and Supermule!

                      1 Reply Last reply Reply Quote 0
                      • S
                        Supermule Banned
                        last edited by

                        You will not be able to copnnect to the servers if a failover scenario occurs….. The configures WAN IP is only applied via DNS to the static IP T1 connection...

                        If you should run CARP(redundancy), you need 3 external IP addr.

                        One of them, is the shared IP for both machines with CARP and failover....

                        1 Reply Last reply Reply Quote 0
                        • E
                          Eugene
                          last edited by

                          I had the same problem once but it was related to bogon networks, my file with non-allocated reanges was not uptodate. Packets dump would definitely help here.

                          http://ru.doc.pfsense.org

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.