Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing Issues

    Scheduled Pinned Locked Moved Routing and Multi WAN
    20 Posts 2 Posters 12.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Offline
      johnpoz LAYER 8 Global Moderator
      last edited by

      that does not return rfc1918.. I returns public..

      ;; QUESTION SECTION:
      ;snipeit.forgeapps.co.uk.      IN      A

      ;; ANSWER SECTION:
      snipeit.forgeapps.co.uk. 14400  IN      A      81.145.129.116

      Is that your IP?

      So what does your webserver resolve that too?  Is unbound asking a forwarded ns, did you forward the domain?  If so when unbound has to ask some other NS in the act of resolving or with a domain override and it returns rfc1918 to unbound that would be a rebind attack..

      From a quick scan I only show 21 open on that IP..

      Not shown: 99 filtered ports
      PORT  STATE SERVICE
      21/tcp open  ftp

      But no welcome message comes back..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07 | Lab VMs 2.8, 25.07

      1 Reply Last reply Reply Quote 0
      • D Offline
        dastrix
        last edited by

        yes this is the ip, however i have no port forward rules set up for ftp?

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          well its shows its open..  And don't see http or https..

          Send a syn to 21, get back a syn,ack.. So something is listning.. Maybe its your modem/router in front of pfsense?

          Nmap scan report for cradley.heathfield.sandwell.sch.uk (81.145.129.116)
          Host is up (0.00078s latency).
          Not shown: 999 filtered ports
          PORT  STATE SERVICE VERSION
          21/tcp open  ftp?
          |_ftp-bounce: no banner

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07 | Lab VMs 2.8, 25.07

          1 Reply Last reply Reply Quote 0
          • D Offline
            dastrix
            last edited by

            Am i able to use reverse proxy for 2 different domain names?

            This is the only other reason i can see it not working?

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by

              I find that highly unlikely since port 80 or https are not even open.. Are you running this domains on some odd port?  in you url?

              I just did a port scan of the top 1000 ports, and only thing answering is 21..

              So unless your using some other IP??  What are these other domains?  Do you have some sort of block in your wan for non UK IPs?  Like pfblocker or something blocking the US?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07 | Lab VMs 2.8, 25.07

              1 Reply Last reply Reply Quote 0
              • D Offline
                dastrix
                last edited by

                Nothing should be blocked for US

                Do i need to create extra NAT Rules for this website?

                As for the port the site is only using standard http port 80.

                I have 2 domain names that i am trying to use reverse proxy for, my primary domain is working fine for all reverse proxy requests etc.

                Seems to be this new domain i have that is not working.

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Post your wan firewall rules..  Like I said scanning your IP shows the ONLY Port that is open is 21..  That is out of nmap 1000 services in the intense scan template..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07 | Lab VMs 2.8, 25.07

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    dastrix
                    last edited by

                    Attached

                    ![Screen Shot 2016-12-12 at 15.50.39.png](/public/imported_attachments/1/Screen Shot 2016-12-12 at 15.50.39.png)
                    ![Screen Shot 2016-12-12 at 15.50.39.png_thumb](/public/imported_attachments/1/Screen Shot 2016-12-12 at 15.50.39.png_thumb)

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      well your firewall rule shows ok, but don't see any states on it.. So nobody on your website..  What I can tell you is those ports are not open from the internet.. I can not get to them.. I have to assume all your domains resolve to that IP.

                      I do not show those ports open.. So is your isp blocking them now?  Do you have something in front of pfsense.  Is your reverse proxy not running?  I get no answer when I send syn to those ports.. If something was there listening, even if didn't know where to send me would get a syn,ack back so I could send it the url I wanted to go too.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        dastrix
                        last edited by

                        Ok so i have called ISP and they don't block anything.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          dude run your own scan, go to canyouseeme.org..  What IP comes up in the box?  Is that your IP your domains are pointing too?  Again I scanned that IP and port 80 is not listening..

                          Here I just did it from another online scanner.. those 3 ports your firewall shows open 80,443,8080 all come back as filtered!!!  Ie nothing listening.. Notice no packets came back..

                          Starting Nmap 6.00 ( http://nmap.org ) at 2016-12-13 13:48 EET
                          Initiating SYN Stealth Scan at 13:48
                          Scanning cradley.heathfield.sandwell.sch.uk (81.145.129.116) [3 ports]
                          Completed SYN Stealth Scan at 13:48, 2.83s elapsed (3 total ports)

                          [+] Nmap scan report for cradley.heathfield.sandwell.sch.uk (81.145.129.116)
                          Host is up.

                          PORT    STATE    SERVICE
                          80/tcp  filtered http
                          443/tcp  filtered https
                          8080/tcp filtered http-proxy

                          Nmap done: 1 IP address (1 host up) scanned in 5.44 seconds
                                    Raw packets sent: 6 (264B) | Rcvd: 0 (0B)

                          I would validate that is your actual IP..  Maybe your IP changed!!  Is your reverse proxy running and listening on those ports?  Because get nothing back from that IP on those ports

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07 | Lab VMs 2.8, 25.07

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.