Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access NAT'd URL from inside network

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 6 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      inzel
      last edited by

      I have a feeling this is not going to work but here it goes anyways. I have a webserver inside my network. I have a NAT setup to forward the service on a certain port to that server. I need to be able to make changes to that server from inside the lan and test it inside the lan. The reason for this is because I usually work on it while Im at home.

      Does anyone have any idea on how I can manage it from the URL instead of the local ip? I would really like to hear if anyone has any options for this.

      Thank you in advance.

      1 Reply Last reply Reply Quote 0
      • E Offline
        Efonnes
        last edited by

        If you are on pfSense 2 or later, the easiest way would be either enabling NAT reflection for just that rule or enabling it globally for all rules at System: Advanced: Firewall/NAT.  On earlier versions, there is only the global option at System: Advanced.  Unless you are sure you will want it enabled for all rules, I'd recommend only enabling it for the rules you know you want it on (if using a version where that is possible).

        1 Reply Last reply Reply Quote 0
        • I Offline
          inzel
          last edited by

          I tried that and I did not see the change. I am unable to access my web url from inside the network. Weird deal. Do I need to restart the firewall or anything like that?

          1 Reply Last reply Reply Quote 0
          • I Offline
            inzel
            last edited by

            Reboot did not work either. Ill keep on trying different things

            1 Reply Last reply Reply Quote 0
            • S Offline
              Supermule Banned
              last edited by

              Can you post logs???

              Try it on pfsense 1.2.3 See if it changes behavior.

              1 Reply Last reply Reply Quote 0
              • I Offline
                inzel
                last edited by

                So, after about an hour of not changing anything, it started working perfectly. I dont know exactly why, but I am happy.

                Thanks for the ideas and help

                1 Reply Last reply Reply Quote 0
                • I Offline
                  inflamer
                  last edited by

                  @inzel:

                  So, after about an hour of not changing anything, it started working perfectly. I dont know exactly why, but I am happy.

                  Thanks for the ideas and help

                  That probably means that a previous state existed which related to one of the NAT rules, which eventually timed out and things started working.

                  -Andreas

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Seems your nat reflection is working now.  But vs hitting your pfsense box and then just get reflected back in.  It simpler if you ask me to just setup your local dns to resolve your fqdn you trying to hit to the local IP.

                    example http://www.publicdomain.com resolves to 1.2.3.4 on the public internet, and 1.2.3.4 is your wan interface IP.

                    Just setup your local dns or even just a host file on your client to resolve www.publicdomain.com to your private address for example 192.168.1.37 (whatever private IP your server is on)

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                    1 Reply Last reply Reply Quote 0
                    • N Offline
                      namezero111111
                      last edited by

                      Either way might get complicated. I personally prefer NAT reflection over split horizon DNS, as johnpoz suggested.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.