Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Mail server with different gateway

    Scheduled Pinned Locked Moved NAT
    5 Posts 4 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      ketchapay
      last edited by

      We have 2 WAN connections โ€“ one is protected by pfSense and the other one with Fortigate. The email server uses the Fortigate as its gateway. I wanted to create a redundancy for inbound mail -- allow both firewalls to accept SMTP. Is this possible?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        That wouldn't work, really, unless both WANs were hooked directly into pfSense.

        When pfSense has a port forward in to a local server on two WANs, it uses pf's reply-to tag to know which WAN the traffic should go back out of, so it can leave the same way it came in.

        If you have two separate routers pushing traffic in to one server, it wouldn't have any way to know which gateway to send the traffic out through, it would always use its default gateway.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • S Offline
          shamims
          last edited by

          Jimp is right. It will not work unless you are using ONE pf box for both the WANs.

          please check my other post at http://forum.pfsense.org/index.php/topic,32043.msg165978.html#msg165978

          Thanks

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG Offline
            GruensFroeschli
            last edited by

            Wouldn't it work if you do a normal port-forward on the pfSense and then add an outbound NAT rule to NAT all traffic from the WAN to the LAN?
            This way the traffic would look to the server as if it originates in the local subnet.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              It may work (if the other router is their default gateway) but you would lose all client information. All e-mail would appear to be connecting from the firewall, which may break any kind of trusted network or spam filtering setup that relies on having that information be accurate.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.