Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    nat for 2 email servers with just 1 wan?

    NAT
    5
    12
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • perikoP
      periko
      last edited by

      Hi guys.

      I have 2 email servers for different domains.

      1 pfsense with 1 wan.

      Is possible to NAT traffic for both servers using the same email ports 465/993 on each one?

      Or is possible to deal with something like this?

      Thanks for your time.

      Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
      www.bajaopensolutions.com
      https://www.facebook.com/BajaOpenSolutions
      Quieres aprender PfSense, visita mi canal de youtube:
      https://www.youtube.com/c/PedroMorenoBOS

      GertjanG 1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Not that I'm aware of. You could possibly arrange for another public IP address from your ISP, and then add that as a VIP. Then you could create NAT rules to handle both servers.

        perikoP 1 Reply Last reply Reply Quote 0
        • GrimsonG
          Grimson Banned
          last edited by

          You can have 1 mail server in front accept mails for both domains, and then if separation is required forward the mails to the actual mail server for each domain.

          This can not be solved by NAT.

          perikoP 1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            Never tried it but should be possible with HAProxy.

            -Rico

            GrimsonG 1 Reply Last reply Reply Quote 0
            • perikoP
              periko @Grimson
              last edited by

              @grimson u mean add a extra email server that will accept the connection and them forward the traffic base on something to email1 or email2 ?

              Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
              www.bajaopensolutions.com
              https://www.facebook.com/BajaOpenSolutions
              Quieres aprender PfSense, visita mi canal de youtube:
              https://www.youtube.com/c/PedroMorenoBOS

              1 Reply Last reply Reply Quote 0
              • perikoP
                periko @KOM
                last edited by

                @kom here with scenario we need 2 wans to manage the traffic for each email server right?

                Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
                www.bajaopensolutions.com
                https://www.facebook.com/BajaOpenSolutions
                Quieres aprender PfSense, visita mi canal de youtube:
                https://www.youtube.com/c/PedroMorenoBOS

                KOMK 1 Reply Last reply Reply Quote 0
                • RicoR
                  Rico LAYER 8 Rebel Alliance
                  last edited by

                  No, if your ISP can route multiple IPs to you say they give you a /30 or /29 network all can be handled with one WAN interface.

                  -Rico

                  perikoP 1 Reply Last reply Reply Quote 0
                  • GrimsonG
                    Grimson Banned @Rico
                    last edited by Grimson

                    @rico said in nat for 2 email servers with just 1 wan?:

                    Never tried it but should be possible with HAProxy.

                    I've only seen HAProxy for load-balancing purposes on mail servers, not to distribute the mails to different servers based on the sender/receiver address.

                    @periko said in nat for 2 email servers with just 1 wan?:

                    @grimson u mean add a extra email server that will accept the connection and them forward the traffic base on something to email1 or email2 ?

                    https://en.wikipedia.org/wiki/SMTP_proxy

                    1 Reply Last reply Reply Quote 0
                    • perikoP
                      periko @Rico
                      last edited by

                      @rico can u please give more details in case we have other IP available and want to use the VIP u mention?👂

                      Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
                      www.bajaopensolutions.com
                      https://www.facebook.com/BajaOpenSolutions
                      Quieres aprender PfSense, visita mi canal de youtube:
                      https://www.youtube.com/c/PedroMorenoBOS

                      1 Reply Last reply Reply Quote 0
                      • KOMK
                        KOM @periko
                        last edited by

                        @periko Call your ISP and ask them how much it would cost for them to assign & route to you another IP address. It should be no problem if it is a business account. Then you simply add it to pfSense as a Virtual IP - IP Alias.

                        perikoP 1 Reply Last reply Reply Quote 0
                        • perikoP
                          periko @KOM
                          last edited by

                          @kom I will check this, thanks.

                          Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
                          www.bajaopensolutions.com
                          https://www.facebook.com/BajaOpenSolutions
                          Quieres aprender PfSense, visita mi canal de youtube:
                          https://www.youtube.com/c/PedroMorenoBOS

                          1 Reply Last reply Reply Quote 0
                          • GertjanG
                            Gertjan @periko
                            last edited by

                            @periko said in nat for 2 email servers with just 1 wan?:

                            Is possible to NAT traffic for both servers using the same email ports 465/993 on each one?

                            These are ports to deposit mail for sending (smtps) and consulting mails on a mailbox/server imaps (993).

                            These two ports are probably used by fat-mail-clients like Outlook or Thunderbird.
                            Take the more intelligent (smaller ?) user (== domain ?) group of your 2 mail servers, and say to these guys : "Hey, guys, if you see somewhere that mentions port '993', change it for 994' - idem for 465, make that 466."
                            Now you can NAT easily on your side.

                            Most people don't care less what they have to choose, they only setup a mail clients ones, and will redo it when their computer breaks down after X years. They don't know why its "465" or "993" anyway.

                            Note : this won't work if it concerns port 80 or 443 .... people don't know that they use these ports several times a day

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.