Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Load balancer and Nat Reflection

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Arjen
      last edited by

      Reflection works fine (if port forwarding is set to only TCP..  TCP&UDP wont work) on all carp vips.

      but;

      if i create a load balanced Virtual server with Carp VIP then reflection is not working. the load balanced cluster i not reachable from the LAN on his external WAN ip adres.

      Is there some sollution for this problem ?

      1 Reply Last reply Reply Quote 0
      • ?
        Guest
        last edited by

        Yep, stop using NAT reflection, use a split-horizon DNS setup instead.

        1 Reply Last reply Reply Quote 0
        • A
          Arjen
          last edited by

          yes thats a option, next problem:

          load balacing
          in: external ip (carp vip) on WAN
          balance: 2x internal ip on LAN

          work OK.

          Load balacing:
          in: internal ip (carp vip on LAN)
          balance: 2x internal ip on LAN

          is not working…

          is this a know problem that load balancing on a internal ip (port 80) to 2 other internal ip's is not working?

          Regards

          Arjen

          ------------------ Lack of NAT Reflection

          pfSense 1.2 implements server load balancing entirely in pf using NAT. It does not, however, automatically add NAT reflection rules even when NAT reflection is enabled in the Advanced section. (That parameter applies only to Port Forward NAT rules.) This means that you will not be able to connect to your virtual server from the same network on which your real servers reside.

          You can add the reflection rules manually in the "Outbound" NAT section, however. For more details on why you cannot connect internally and what rules need to be added manually, see Redirection and Reflection section of the pf manual.
          –----------------

          is there any info about how to create the reflection rules in the outbound nat section ?

          1 Reply Last reply Reply Quote 0
          • A
            Arjen
            last edited by

            nobody ??  :-\

            howto create manual reflection rules…

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              Seems like a pretty convoluted way to get things done when split-dns would handle it better…

              http://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks%3F

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.