Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ddns + port forwarding

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 2 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      byaxe
      last edited by

      Hi.
      I have domain in ddns.net, let say it was domain.ddns.net
      I have LAN with many www or other servers. For each i have diferent port forwarding for that…example:
      server1: 192.168.1.3
      server2: 192.168.1.4

      In port forwarding i forward port 8003 to 192.168.1.3, and 8004 to 192.168.1.4

      When i acces domain.ddns.net:8003 or domain.ddns.net:8004 outside my net, everything works fine, but when i access it from my lan it doesn't work.
      I read about pure nat and dns forwarder but pure nat do not work, and dns forwarder with different port can't be configured.
      I supposed i do something wrong, but please tell/write me what. I need same outsied/inside addres so i can test everything work.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        NAT Reflection should work for you there.

        https://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks

        That could also be made to work with port forwards on LAN (the interface with the clients on it) but it would be a LOT cleaner if the connecting clients and the destination servers were on different subnets.

        Example:

        Local/inside DNS entry for my_bitchen_server.com is a VIP on LAN of 192.168.1.2
        Servers are on OPT1 on 192.168.2.100 and 192.168.2.101

        Port forward on LAN source LAN Net dest 192.168.1.2 port 8000 NAT address 192.168.2.100 port 80
        Port forward on LAN source LAN Net dest 192.168.1.2 port 8001 NAT address 192.168.2.101 port 80

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • B
          byaxe
          last edited by

          Thanks for reply. I do exactly what it is on that link. I do NAT reflection but it doesn't work. I could access from outside, but i can't access from inside. I couldn't do different subnets because i access from the same host where is the www server

          1 Reply Last reply Reply Quote 0
          • B
            byaxe
            last edited by

            And now it work's. I do nothing, and just start working.

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              Amazing.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • B
                byaxe
                last edited by

                Ok. Found my miracle. One firewall rules block this.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.