Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Odd out side world but no loop back can see

    General pfSense Questions
    4
    14
    3.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      Fmslick
      last edited by

      ;D hi.
      ok so this is a bit odd to me but i have a web server running and a minecraft
      now they can talk to the outside work and ppl can join my minecraft server and can see the web server BUT
      when i try to look back in from URL: http://ns1-fmslick.zapto.org/  i get an error | pinging the IP & URL works too BBUUTT if i use a proxy like http://www.proxysites.net/visit/6/ it works and i can see the index.html file that say "hello world" and and i can see the site on my LAN-IP too ….... so i am hella lost here could my firewall be blocking my WAN-IP keeping me from seeing the site? or wtf?

      Proxy working SS
      http://prntscr.com/1zxpv2

      Ping working
      http://prntscr.com/1zxr4g

      site on my side looping back not working
      http://prntscr.com/1zxr8v

      We all start same where

      1 Reply Last reply Reply Quote 0
      • N
        nothing
        last edited by

        It doesn't work because it redirects to inside network. I guess turning on NAT reflection should make it work.

        1 Reply Last reply Reply Quote 0
        • F
          Fmslick
          last edited by

          @nothing:

          It doesn't work because it redirects to inside network. I guess turning on NAT reflection should make it work.

          What are you talking about?

          it works and i can see that from a friends house, it is just not working for me on the same network as the server…

          We all start same where

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            That's exactly what Nothing said.
            It doesn't work from inside the network if you try to access it via URL because the URL redirects to your external IP.

            https://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks%3F

            Steve

            1 Reply Last reply Reply Quote 0
            • F
              Fmslick
              last edited by

              @stephenw10:

              That's exactly what Nothing said.
              It doesn't work from inside the network if you try to access it via URL because the URL redirects to your external IP.

              https://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks%3F

              Steve

              Your right, Sorry about that "Nothing" i i was hella sleepy when i happen to read you the post you made, but now that  "stephenw10" points it out you are right and i see what i am doing wrong or should i say what i missed lol Thanks guys.

              We all start same where

              1 Reply Last reply Reply Quote 0
              • J
                jasonlitka
                last edited by

                If possible, try and work without NAT reflection. The preferred method would be Split DNS.

                I can break anything.

                1 Reply Last reply Reply Quote 0
                • F
                  Fmslick
                  last edited by

                  @Jason:

                  If possible, try and work without NAT reflection. The preferred method would be Split DNS.

                  Got it working with NAT Reflection: (NET + Proxy) but like you said "The preferred method would be Split DNS" however i turn it back off an have been goofing with DNS forwarder settings to see if i can get it to work but its still a no go :(

                  My settings as of now!
                  http://prntscr.com/204hnu

                  part2
                  http://prntscr.com/204hsf

                  part3
                  http://prntscr.com/204hx6

                  We all start same where

                  1 Reply Last reply Reply Quote 0
                  • N
                    nothing
                    last edited by

                    You should add DNS override for "ns1-fmslick.zapto.org" (or whatever is the record you need) as that's the name you are calling from both inside and outside network.

                    1 Reply Last reply Reply Quote 0
                    • F
                      Fmslick
                      last edited by

                      @nothing:

                      You should add DNS override for "ns1-fmslick.zapto.org" (or whatever is the record you need) as that's the name you are calling from both inside and outside network.

                      How or can you send me a link? so i have something to read more about what you are talking bout & i am using no-ip.com for the domain at this time so idk if that matters or not?

                      We all start same where

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Whatever URL you are using to point at your WAN IP that's what you have to override when accessing it from the LAN.

                        Such that when your internal client tries to access ns1-fmslick.zapto.org (or whatever URL you're using) the DNS forwarder will point it to the local server instead on the WAN IP.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • N
                          nothing
                          last edited by

                          You almost did it here http://prntscr.com/204hx6
                          The point is to "fake" the fqdn provided by no-ip.
                          Instead of fmslick.lan put there ns1-fmslick.zapto.org then flush your PC dns cache or restart and it should be working.

                          What you get in the end is:
                          From inside network ns1-fmslick.zapto.org = 192.168.1.51
                          From Internet ns1-fmslick.zapto.org = 213.44.55.66 (or whatever your real IP is)

                          1 Reply Last reply Reply Quote 0
                          • F
                            Fmslick
                            last edited by

                            @stephenw10:

                            Whatever URL you are using to point at your WAN IP that's what you have to override when accessing it from the LAN.

                            Such that when your internal client tries to access ns1-fmslick.zapto.org (or whatever URL you're using) the DNS forwarder will point it to the local server instead on the WAN IP.

                            Steve

                            Ok i see what your talking about.

                            @nothing:

                            You almost did it here http://prntscr.com/204hx6
                            The point is to "fake" the fqdn provided by no-ip.
                            Instead of fmslick.lan put there ns1-fmslick.zapto.org then flush your PC dns cache or restart and it should be working.

                            What you get in the end is:
                            From inside network ns1-fmslick.zapto.org = 192.168.1.51
                            From Internet ns1-fmslick.zapto.org = 213.44.55.66 (or whatever your real IP is)

                            ok i did what you said but still not working.
                            http://prntscr.com/205648

                            but i can use lampu.ns1-fmslick.zapto.org and see it so that is cool with me, i don't really have to see it with the ns1-fmslick.zapto.org as long as the outside would can .. Thanks guys  ;D

                            We all start same where

                            1 Reply Last reply Reply Quote 0
                            • N
                              nothing
                              last edited by

                              host: ns1-fmslick
                              domain: zapto.org

                              1 Reply Last reply Reply Quote 0
                              • F
                                Fmslick
                                last edited by

                                @nothing:

                                host: ns1-fmslick
                                domain: zapto.org

                                That worked 100% Thanks. lol
                                http://prntscr.com/205ewf

                                We all start same where

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.