Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT Reflection, if I can't use Split DNS?

    Scheduled Pinned Locked Moved NAT
    6 Posts 4 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fips
      last edited by

      Hey,

      my setup:

      Pfsense with a LAN Interface (192.168.1.0/24) and two VLANs (VLAN 100: 10.0.0.1/24 and VLAN 200: 10.0.0.2/24).
      Mailserver has a LAN IP 192.168.1.100.

      All LAN Clients can of course enter that Mailserver via its local IP (through Split DNS).
      External via its public address.

      I blocked all traffic between both VLANs and the normal 192.168.1.0 LAN.
      How can Clients form VLAN connect to that Mailserver?
      I enabled in that 1:1 entry, NAT Reflection, but it doesn't work.

      For sure I made a stupid mistake but I can't see the wood for the trees ;-)

      Thanks

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Why don't you provide the internal DNS to the VLANs?

        Off course you need firewall rules to allow access to DNS and the Mailserver.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          "How can Clients form VLAN connect to that Mailserver?"

          Why would you not let your other vlans talk to your mailserver via its local IP.. Set you rules to allow the traffic you want.. Is just plain stupid to not allow that traffic if your going to allow the traffic from the internet anyway.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • F
            fips
            last edited by

            @johnpoz:

            "How can Clients form VLAN connect to that Mailserver?"

            Why would you not let your other vlans talk to your mailserver via its local IP.. Set you rules to allow the traffic you want.. Is just plain stupid to not allow that traffic if your going to allow the traffic from the internet anyway.

            Well ok, I can allow traffic between Mailserver and VLANs.
            It was more a principle thing..can it work…how is it

            This was my first attempt with NAT Reflection, I just wanted to try it  ;)

            1 Reply Last reply Reply Quote 0
            • N
              NOYB
              last edited by

              @fips:

              … two VLANs (VLAN 100: 10.0.0.1/24 and VLAN 200: 10.0.0.2/24).

              Is this what is actually configured?  Or is it a typo?

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                As to nat reflection trying it?  Why?  Its pointless, and to be honest an abomination to good networking.. Pfsense should just drop the support all together like they did with the ftp proxy/helper ;)

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.