Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dual IP email server with LAN?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    13 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      killmasta93
      last edited by

      Hi,
      I was wondering if someone could assit on what i might be doing wrong?

      So right now i have pfSense box with 2 network cards, one is the WAN and the other is the email server IP, I have users navigate though the WAN while the email server (192.168.3.150) sends out email using the static IP 200.116.3.xxx. The issue is that when pfSense reboots and come back online the users some how are navigating with the 200.116.3.xxx instead of the 181.137.104.xxx.

      The only way to fix this is reboot the modem of the lSP but its a hassale sometimes, so i thought maybe it could be the NAT config or the lan rules using the gateway which i tried see pictures

      Thank you
      Clipboarder.2016.12.18-003.png_thumb
      Clipboarder.2016.12.18-003.png
      Clipboarder.2016.12.18-002.png_thumb
      Clipboarder.2016.12.18-002.png
      Clipboarder.2016.12.18.png_thumb
      Clipboarder.2016.12.18.png

      Tutorials:

      https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        So in your gateways do you have them both set as default?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

        1 Reply Last reply Reply Quote 0
        • K Offline
          killmasta93
          last edited by

          Thanks for the reply, I think that the WAN is the default gateway which is the IP I want users to navigate with the 181.xx.xx.xx see picture

          Thank you

          Clipboarder.2016.12.18-004.png
          Clipboarder.2016.12.18-004.png_thumb

          Tutorials:

          https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            "Outbound NAT determines how traffic leaving a pfSense system will be translated.

            Outbound NAT does not control which interface traffic will leave, only how traffic is handled as it exits. To control which interface traffic will exit, use policy routing or Static Routes."

            What are the rules on the 192.168.3.0/24 interface?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • K Offline
              killmasta93
              last edited by

              Thanks for the reply, As rules for the rules on my LAN, I have the email server 192.168.3.150 going out with the IP of 201.xx.xx.xx no issue there, but its the navigation of the LAN that i cannot get it though the WAN (181.xx.xx.xx) I was looking on routing but on the note it says

              Do not enter static routes for networks assigned on any interface of this firewall

              So im guessing that not it?

              Thank you

              Clipboarder.2016.12.19.png
              Clipboarder.2016.12.19.png_thumb

              Tutorials:

              https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                What's in the WPAD port alias?

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • K Offline
                  killmasta93
                  last edited by

                  thanks for the reply, its blocking port 443

                  Tutorials:

                  https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    Nobody on your LAN will be able to use https then.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • K Offline
                      killmasta93
                      last edited by

                      true because i force them to use WPAD meaning facebook or any https site i want to block i can as long as they auto detect the proxy and anything else goes though transparent port 80

                      Tutorials:

                      https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        OK so what, exactly, is not working? Now we have squid in the mix there.

                        Like right now. what is broken? Specifically.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • K Offline
                          killmasta93
                          last edited by

                          well nothing is really broken, so normally i have users navigate on 181.xx.xx.xx which is the WAN and the email server IP which is on another NIC gives out an IP of 201.xx.xx.xx, Whats odd or funny when pfSense reboots some how users start navigating with the 201.xx.xx.xx not sure why, so what i have to do is reboot the lSP modem wait around 10min and then users start navigating on the 181.xx.xx.xx. I guess my question is why does that change when pfSense reboots, when the NICs are completely  different and on pfSense shows the WAN with 181.xx.xx.xx.

                          Thank you

                          Tutorials:

                          https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ Offline
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Well its a gateway right, if wan is down it can use the other gateway.. You don't have any rules that says it can't use it.  Or to use a specific gateway.  Your hybrid nats say nat only your email server, but what does the automatic nats say, etc.

                            If you don't want your other devices using a gateway when the other gateway is down, then put in the rules that they can only use that specific gateway..

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                            1 Reply Last reply Reply Quote 0
                            • K Offline
                              killmasta93
                              last edited by

                              Thanks for the reply, So if i understood correctly I would need to go to pfSense then go to routing and find  a way to route the LAN to use only that Gateway?

                              What very odd this is only happens when pfSense reboots, the only way to get it the way i want, if i reboot the lSP modem a few times which its a pain

                              Thank you

                              Tutorials:

                              https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.