Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Some external hosts can connect through WAN, others can't

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 4 Posters 4.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Supermule Banned
      last edited by

      If it is LAN users that cannot connect, it is because Pfsense cannot do packet inspection with Layer7 over the same interface….In short, it cannot analyze the packets and send them back to the mailserver.

      You can overcome that, by either using VLAN enabled switch, optional NIC or find Layer7 capable firewall... :)

      1 Reply Last reply Reply Quote 0
      • S
        schnarky42
        last edited by

        @Cry:

        Sounds like a problem outside your LAN.

        Do you run your webmail on port 80/TCP or port 443/TCP?  Doe the locations that people can't connect from have anything in common (ie, are they all places of work, wireless hot-spots, etc)?

        Internally across the LAN, everyone can connect fine. It's outside access that is problematic. Webmail runs across port 443. The places that seem to have problems are people who work from home and use residential DSL/Cable. We have a co-location server and that server can access everything fine. We also have a satellite office that can access everything as well.

        1 Reply Last reply Reply Quote 0
        • S
          schnarky42
          last edited by

          Firewall and NAT settings if this helps any. Disabling the RFC1918 and Bogon rule did not solve the issue either. We also have load balancing with failover on opt1 with cable; could that cause this problem?

          firewallcrop.PNG
          firewallcrop.PNG_thumb
          natcrop.PNG
          natcrop.PNG_thumb

          1 Reply Last reply Reply Quote 0
          • S
            Supermule Banned
            last edited by

            That depends on the external IP and DNS settings for the loadbalancer….

            1 Reply Last reply Reply Quote 0
            • Cry HavokC
              Cry Havok
              last edited by

              Time for a network diagram too I think, you've mentioned important details in a later post that you overlooked at the beginning ;)

              1 Reply Last reply Reply Quote 0
              • S
                schnarky42
                last edited by

                Here's a quick diagram, will this work?

                T1 - Static IP–----- WAN-----|
                                                          |
                                                            Load balance & Failover --- LAN Subnet
                                                          |
                Cable - DHCP------- OPT1----

                1 Reply Last reply Reply Quote 0
                • Cry HavokC
                  Cry Havok
                  last edited by

                  So:

                  1. Where's your server - on the LAN?
                  2. What connection to people use to connect to the server - T1 or Cable?
                  3. If you run a packet capture on that interface, do you see the packets that don't reach the pfSense host?
                  1 Reply Last reply Reply Quote 0
                  • S
                    schnarky42
                    last edited by

                    @Cry:

                    So:

                    1. Where's your server - on the LAN?
                    2. What connection to people use to connect to the server - T1 or Cable?
                    3. If you run a packet capture on that interface, do you see the packets that don't reach the pfSense host?

                    1.) Yes, all servers are within the LAN, no DMZ. I can detail the network diagram when I have some spare time later today.
                    2.) From the outside, people connect to the server via the T1. I setup the NAT and firewall rules accordingly (see the NAT/Firewall images in my previous post)
                    3.) I'll have to switch back in PFsense and run capture over the weekend, as of right now our Pix is in and using the T1.

                    Thanks for your help so far Cry and Supermule!

                    1 Reply Last reply Reply Quote 0
                    • S
                      Supermule Banned
                      last edited by

                      You will not be able to copnnect to the servers if a failover scenario occurs….. The configures WAN IP is only applied via DNS to the static IP T1 connection...

                      If you should run CARP(redundancy), you need 3 external IP addr.

                      One of them, is the shared IP for both machines with CARP and failover....

                      1 Reply Last reply Reply Quote 0
                      • E
                        Eugene
                        last edited by

                        I had the same problem once but it was related to bogon networks, my file with non-allocated reanges was not uptodate. Packets dump would definitely help here.

                        http://ru.doc.pfsense.org

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.