Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't access resources with our domain name from inside the network

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 3 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      V4705
      last edited by

      Hi, I used to have a solution for that with NAT but for some reason it's not working anymore.
      I'd like to access our web pages using our domain name, from inside the network.
      I can still access them using the internal IP of the server, or with the domain name when I'm outside the LAN.

      That's the NAT rule that I think used to work, but correct me if something is incorrect or I need to configure anything else:

      if: wan
      protocol: tcp/udp
      source address: any
      source port: any
      destination address: my wan ip (alias for my a record)
      destination port: 443
      nat ip: my server internal ip
      nat port: 443

      DNS is probably not the issue because I tried to browse my WAN IP too.

      1 Reply Last reply Reply Quote 0
      • A Offline
        arduino
        last edited by

        In Setup >> Advanced >> Networking there is a setting for proxy NAT at the bottom.

        1 Reply Last reply Reply Quote 0
        • V Offline
          V4705
          last edited by

          Ok I think the problem was "Block private networks" on WAN interface :X
          Maybe its because now with Comcast I have a modem with 2 IP(s) and the LAN is connected to the modem and receiving the 2nd IP, so the incoming connection from LAN and WLAN (comcast wifi) considered as private network?… not sure...

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            with Comcast I have a modem with 2 IP(s) and the LAN is connected to the modem and receiving the 2nd IP, so the incoming connection from LAN and WLAN (comcast wifi) considered as private network?

            Huh?  You lost me as to your actual topology there.

            Private IPs are just RFC1918:  10.0.0.0/8 172.16.0.0/12 192.168.0.0/16

            If you are connected to something outside your WAN, are receiving an RFC1918 address and are not NATted to a public IP, and attempting to make a connection into your WAN to a port forward then yes, you need to turn off block private networks on your WAN.

            Blocked connections from the private IP should show up in the firewall logs.

            When inside your network does your server DNS resolve to internal or external IP?  If external, you need NAT reflection.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.