Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Auto create nat reflectioin rules for virtual servers?

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    5 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jon
      last edited by

      Hello,

      I am wanting to use pfsense to load balance our webfarm using the virtual server/pool feature, but internal users need to be able to access the servers as well. I notice that If i used a host group and just did a nat forward it creates reflect rules. It doesnt create them for virtual servers though. I can add them in by hacking the config files , but would rather have a official option available. This is the only thing keeping me from using the load balancer at the moment is the lack of reflection rules for it. Would this be possible to add?

      Thanks alot!

      -Jon

      1 Reply Last reply Reply Quote 0
      • D
        dzeanah
        last edited by

        Would it be possible to set up another load balancer for inside that redirects to the same machines?

        1 Reply Last reply Reply Quote 0
        • J
          Jon
          last edited by

          I could setup another pair of machines to load balance in front of the webservers, but seems like alot to invest to get reflected clients to work. hacking in the inetd entries/outbound rdr rule the same way the system adds them when forwarding to a alias works well, just dont like having to readd the modifications every time I upgrade.

          1 Reply Last reply Reply Quote 0
          • D
            dzeanah
            last edited by

            I guess I wasn't clear.  Let me try again:

            Let assume 3 networks: WAN, LAN, and DMZ.

            So, right now you can go to services -> load balancer -> virtual servers and you've got a pool of servers set to answer on a public IP address, right?

            Why not go to the same place, click the "duplicate entry" button, and change the IP address on the new entry to one on your LAN instead?

            That way you've got the same pool of servers listening on a WAN ip address and a LAN ip address.

            1 Reply Last reply Reply Quote 0
            • J
              Jon
              last edited by

              I tried this, but wasnt able to get relayd to accept and forward connections through the same interface. When configured to listen on the lan interface, it wasnt able to forward connections out the same interface, even with permit rules added to the LAN interface allowing all traffic to the hosts on the same network.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.