Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    cant get access from outside to webpage

    Scheduled Pinned Locked Moved General pfSense Questions
    haproxyacmefirewall rules
    19 Posts 2 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      If you enable logging on those pass rules on those pass rules then traffic that is matched and passed will be shown in the firewall log.

      However you can see from the state counters there that nothing had been passed by them when that screenshot was taken.

      It looks like no traffic is arriving on the WAN for ports 80 or 443. Check the ISP router is actually passing it.

      Steve

      P 2 Replies Last reply Reply Quote 0
      • P
        pooperman @stephenw10
        last edited by

        @stephenw10
        i am very sure it is not related to ISP router, as port 443 for openvpn never had any issues.

        however, i put it into DMZ mode, so there is absolutely nothing what might block it.

        still no sucess.

        1 Reply Last reply Reply Quote 0
        • P
          pooperman @stephenw10
          last edited by

          @stephenw10
          when I use anschreikurse.duckdns.org from phone I get a warning for certificate is untrusted. I checked the cert and it is the root CA from pfSense.

          If I click yes continue unsafe, it shows me loginpage of pfsense.

          So that shows me, isp router is working fine and dns resulution is also working

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            I assume that screenshot was taken before you had tested that then as there are no connections shown.

            Ok, you will need to change the port the pfSense GUI is listening on in Sys > Adv > Admin Access. You cannot have nginx and HAProxy both listening on 443.
            HAProxy will logged that. It would have failed to start the frontend on 443.

            Steve

            P 1 Reply Last reply Reply Quote 0
            • P
              pooperman @stephenw10
              last edited by

              @stephenw10
              good point!

              i havent seen any notification but yes makes sense. so pfsense login is now on different port.

              I came to the setting nat reflection mode for port forwards under admin advanced

              it is set to disabled. is that correct?

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                That's the default setting. You do not need NAT reflection here at all, HAProxy proxies the traffic is does not forward it.

                Steve

                P 1 Reply Last reply Reply Quote 0
                • P
                  pooperman @stephenw10
                  last edited by

                  @stephenw10

                  ok got it.

                  now I get 503 service unavailable

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    With the correct certificate?

                    P 1 Reply Last reply Reply Quote 0
                    • P
                      pooperman @stephenw10
                      last edited by

                      @stephenw10

                      I think so

                      1.JPG
                      cert is for anschreikurse.duckdns.org

                      haproxy frontend is also for anschreikurse.duckdns.org
                      backend is nc.anschreikurse.duckdns.org

                      P 1 Reply Last reply Reply Quote 0
                      • P
                        pooperman @pooperman
                        last edited by

                        @pooperman

                        there is some issue with SSL handshake:

                        1.JPG

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.