Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Local port not working

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      Jamerson
      last edited by

      Hi Guys,
      Today we have moved to Pfsense hardware, however the local webserver is only reachable from the outside when using the FQDN,
      internal its not working.
      when we use webserver.domain.com internal it does not work, on a 4G network it doe works.
      when we use the internal IP of the web server it works.

      Firewall rules are set fine because external it does works.
      when we tracer route using the external name it drops when it's reach the Pfsense firewall and comes back up with request time out .
      internal it finish the trace fine.
      can you please advise what wrong ?

      1 Reply Last reply Reply Quote 0
      • D Offline
        doktornotor Banned
        last edited by

        Yeah, your internal DNS is wrong.

        1 Reply Last reply Reply Quote 0
        • KOMK Offline
          KOM
          last edited by

          https://doc.pfsense.org/index.php/Why_can't_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks

          1 Reply Last reply Reply Quote 0
          • J Offline
            Jamerson
            last edited by

            it was a issue with DNS which is fixed now,
            DNS is replicating fine, however i still can't access the webserver.
            when i ping webserver.domain.com it reply with the correct adres which is the external IP.
            when i use the external IP on the browser it does not works, but externally it does.
            isnt it Pfsense routing issue now ?

            can you please advies ?

            1 Reply Last reply Reply Quote 0
            • D Offline
              doktornotor Banned
              last edited by

              @Jamerson:

              when i ping webserver.domain.com it reply with the correct adres which is the external IP.

              No, that is NOT the correct address for pings from your LAN. Way to miss the point, altogether.

              1 Reply Last reply Reply Quote 0
              • J Offline
                Jamerson
                last edited by

                @doktornotor:

                @Jamerson:

                when i ping webserver.domain.com it reply with the correct adres which is the external IP.

                No, that is NOT the correct address for pings from your LAN. Way to miss the point, altogether.

                the webserver Always connected using the external IP adres.
                internal IP works fine, external does not reply.
                isnt this a NAT reflection issue ?
                thank you

                1 Reply Last reply Reply Quote 0
                • D Offline
                  doktornotor Banned
                  last edited by

                  You are supposed to use the local IP when connecting from LAN, and the external IP when connecting from WAN.

                  As for NAT reflection, there are enough threads here discussing that piece of nonsense, not getting into this debate yet again.

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    Jamerson
                    last edited by

                    @doktornotor:

                    You are supposed to use the local IP when connecting from LAN, and the external IP when connecting from WAN.

                    As for NAT reflection, there are enough threads here discussing that piece of nonsense, not getting into this debate yet again.

                    thank you for your answer this has been working for over 4 years, untill we deciede to move to hardware.
                    the external DNS is created to forward to the right IP as following.

                    External DNS records : webserver.domain.com >>>>>> Our External IP >>>> so our users listen connect using the external IP.
                    External DNS Records : webmail.domain.com >>>>>>> Our external IP >>>> Outlook connects using the external IP with autodiscover.

                    the old situation was the ISP router forwrard the 443/80 to the Virtual PFSENSE,  Virtual PFSESE forward the 443/80 to the internal LAN.

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      doktornotor Banned
                      last edited by

                      Perhaps you could finally read https://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks

                      1 Reply Last reply Reply Quote 0
                      • KOMK Offline
                        KOM
                        last edited by

                        You were either using NAT reflection, or you had your internal DNS handing out LAN IPs (known as split DNS).

                        1 Reply Last reply Reply Quote 0
                        • J Offline
                          Jamerson
                          last edited by

                          @KOM:

                          You were either using NAT reflection, or you had your internal DNS handing out LAN IPs (known as split DNS).

                          thank you for your answer,
                          i managed to get this fixed using a internal split brain DNS.
                          much appreciate it your support.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.