Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Manual DNS entry for a local host

    Scheduled Pinned Locked Moved DHCP and DNS
    13 Posts 6 Posters 1.4k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jahonixJ Offline
      jahonix
      last edited by

      @techvic said in Manual DNS entry for a local host:

      So somehow the port forward rules do not apply for requests coming from the same interface as the destination interface is.

      Correct, this would require an active reflection which is off by default. Consider this a hack only.

      A simple workaround would be a manual DNS entry for the webserver-host ...

      You nailed it, it's called host override in your DNS server and works as split DNS.
      The preferred and elegant way of solving this. The linked docs show this in greater detail.

      1 Reply Last reply Reply Quote 0
      • T Offline
        techvic
        last edited by

        thanks, "Method 1: NAT Refelction" was the option I was looking for ( https://docs.netgate.com/pfsense/en/latest/nat/accessing-port-forwards-from-local-networks.html )

        JKnottJ 1 Reply Last reply Reply Quote 0
        • JKnottJ Offline
          JKnott @techvic
          last edited by

          @techvic

          Is there some reason you can't use a host override? By using NAT reflection, you're getting pfSense involved, when it doesn't have to be.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel 1 Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          T 1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            Using nat reflection is like putting the light switch for your bedroom out at the end of the driveway.. So every time you want to turn your bedroom light on or off you need to walk out to the end of the driveway just to come back inside.

            While it works - its not very efficient ;)

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

            1 Reply Last reply Reply Quote 0
            • T Offline
              techvic @JKnott
              last edited by

              @JKnott said in Manual DNS entry for a local host:

              @techvic

              Is there some reason you can't use a host override? By using NAT reflection, you're getting pfSense involved, when it doesn't have to be.

              I looked into that, however it expects a hostname in the scheme "hostname.domain.com", which, in my case is not possible, because "domain.com" IS the hostname. I couldn't find a way to cheat the settings-dialog accordingly. Is that possible?

              GertjanG JKnottJ 2 Replies Last reply Reply Quote 0
              • GertjanG Online
                Gertjan @techvic
                last edited by

                @techvic said in Manual DNS entry for a local host:

                the scheme "hostname.domain.com", which, in my case is not possible, because "domain.com" IS the hostname

                Very non-common - perfect to break something.

                Like you blank out the hostname here :

                46f6e54b-adae-4a17-8d29-4fbbfe0ef984-image.png

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  You understand that when you do that, the domain is the host and .tld is the domain right... Works just fine...

                  hostoveride.jpg

                  While I agree its bad practice to do that to be honest.. It works just fine...

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                  JKnottJ 1 Reply Last reply Reply Quote 0
                  • JKnottJ Offline
                    JKnott @techvic
                    last edited by

                    @techvic said in Manual DNS entry for a local host:

                    @JKnott said in Manual DNS entry for a local host:

                    @techvic

                    Is there some reason you can't use a host override? By using NAT reflection, you're getting pfSense involved, when it doesn't have to be.

                    I looked into that, however it expects a hostname in the scheme "hostname.domain.com", which, in my case is not possible, because "domain.com" IS the hostname. I couldn't find a way to cheat the settings-dialog accordingly. Is that possible?

                    If it's a valid host name, it should work. Have you tried it to see what happens? You can put whatever valid host name you want in there, even google.com. Then any attempts to reach google will go to the address you specified.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel 1 Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    • JKnottJ Offline
                      JKnott @johnpoz
                      last edited by

                      @johnpoz said in Manual DNS entry for a local host:

                      While I agree its bad practice to do that to be honest.. It works just fine...

                      It may be a bad practice, but it's made necessary by NAT on IPv4. You don't have to do such a thing on IPv6, where there are plenty of addresses.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel 1 Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      1 Reply Last reply Reply Quote 0
                      • GertjanG Online
                        Gertjan
                        last edited by

                        @johnpoz : I just tried it : my domain a mere TLD .fr and the rest of the domain as a host name.
                        It ... works.
                        Common sense is still barking to me.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.