Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT LOOPBACK

    Firewalling
    3
    9
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      telvenes
      last edited by

      Let's say I have a VLAN 10 where it is servers that host multiple websites.

      I also have one VLAN 100 which is one public wireless internet.

      with these rules none of the users as VLAN 100 get in on the websites that is located on VLAN 10.

      although I have enabled PURE NAT, how can we fix this?

      Protocol Source Port Destination Port Gateway Queue Schedule

      IPv4 * VLAN_Net * VLAN_Address * * None
      IPv4 * * * This Firewall * * None
      IPv4 * VLAN_Net * !rfc1918 * * None

      1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott
        last edited by

        You have to set up routing between the VLANs.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • T
          telvenes
          last edited by

          Can you please tell me how?

          cant i force trafic to go to internet first than inside again?

          1 Reply Last reply Reply Quote 0
          • T
            telvenes
            last edited by

            Do not completely understand why I cant search the site www.example.com from VLAN 100 when I can do it from a different network.

            What has become nat out in internet suppose to be available on the local network as well.

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              Turn off NAT Reflection entirely and, instead, add an A record to two to your DNS so that the public FQDN of the web servers resolves to the internal IP address.  This is Split DNS.  Then add a rule on the VLAN100 interface that allows it to access just those servers web ports on VLAN10.

              https://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks

              1 Reply Last reply Reply Quote 0
              • T
                telvenes
                last edited by

                @KOM:

                Turn off NAT Reflection entirely and, instead, add an A record to two to your DNS so that the public FQDN of the web servers resolves to the internal IP address.  This is Split DNS.  Then add a rule on the VLAN100 interface that allows it to access just those servers web ports on VLAN10.

                https://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks

                Correct me if I'm wrong, for each server I should NAT to Internet I have to go through all VLAN to create rules for them to get access to servers that already are on the internet?

                The thing is that this is only an example of VLANS, there are plans that it will come very many VLAN and servers/clients gradually so it sounds like it may be difficult to keep up with maintenance

                1 Reply Last reply Reply Quote 0
                • T
                  telvenes
                  last edited by

                  Hello again, tested what you said I must do now. I understand how you want me to do this. But hope you find another way.

                  I have 20 Virtual IP with alot of rules, and for every VLAN in make I literally have to dublicate NAT settings into Rules for each VLAN?

                  1 Reply Last reply Reply Quote 0
                  • T
                    telvenes
                    last edited by

                    screenshot.

                    So this setup works. but i dont understand why i cant add this automaticly

                    100.JPG
                    100.JPG_thumb
                    101.JPG
                    101.JPG_thumb

                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      Correct me if I'm wrong, for each server I should NAT to Internet I have to go through all VLAN to create rules for them to get access to servers that already are on the internet?

                      Yes.  It's definitely more work, but it is the better, more elegant solution.  If for whatever reason you don't want to do that then your only other option is NAT Reflection from that same link I gave you.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.