Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Public networks behind firewall

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 3 Posters 931 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      Krisbe
      last edited by

      Hi

      I have some public /27 networks with web- and mailservers and some other VM's. What is the best method to make them accessible from the internet? I don't want to use NAT. Are there any other options then bridging?

      Thanks

      vallumV JKnottJ 2 Replies Last reply Reply Quote 0
      • vallumV Offline
        vallum @Krisbe
        last edited by

        @krisbe said in Public networks behind firewall:

        Hi

        I have some public /27 networks with web- and mailservers and some other VM's. What is the best method to make them accessible from the internet? I don't want to use NAT. Are there any other options then bridging?

        Thanks

        What is your network topology ? you can use reverse proxy for web and mail servers.

        Manu

        1 Reply Last reply Reply Quote 0
        • K Offline
          Krisbe
          last edited by

          It looks like this.
          Web- and mailservers were a example. There are also multiple FTP servers, SSH servers, DNS servers, VPN servers etc. Not only from us, but also from clients.
          0_1550560158030_nwlayout.png

          vallumV 1 Reply Last reply Reply Quote 0
          • vallumV Offline
            vallum @Krisbe
            last edited by

            @krisbe said in Public networks behind firewall:

            It looks like this.
            Web- and mailservers were a example. There are also multiple FTP servers, SSH servers, DNS servers, VPN servers etc. Not only from us, but also from clients.
            0_1550560158030_nwlayout.png

            Pfsense is in transparent mode ? have you configured public IP's directly on servers ?

            Manu

            1 Reply Last reply Reply Quote 0
            • K Offline
              Krisbe
              last edited by

              Yes indeed, public IP's are configured on the server interfaces.
              Transparent mode == bridging WAN and OPT1?

              vallumV 1 Reply Last reply Reply Quote 0
              • vallumV Offline
                vallum @Krisbe
                last edited by vallum

                @krisbe said in Public networks behind firewall:

                Yes indeed, public IP's are configured on the server interfaces.
                Transparent mode == bridging WAN and OPT1?
                Yes

                You can configure haproxy package available in pfsense to act as frontend for all those servers.
                you can assign public ip's as virtual Ip's in pfsense for wan interface, so that It can accept request and forward it to backend servers(web servers, mail , ftp{for ftp check for ports PASSV or ACTIVE} etc). you can read more about in forums.

                Manu

                1 Reply Last reply Reply Quote 0
                • JKnottJ Offline
                  JKnott @Krisbe
                  last edited by

                  @krisbe said in Public networks behind firewall:

                  I don't want to use NAT. Are there any other options then bridging?

                  Just turn off NAT, as described here.

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  vallumV 1 Reply Last reply Reply Quote 0
                  • vallumV Offline
                    vallum @JKnott
                    last edited by

                    @jknott said in Public networks behind firewall:

                    @krisbe said in Public networks behind firewall:

                    I don't want to use NAT. Are there any other options then bridging?

                    Just turn off NAT, as described here.

                    how would that help?

                    Manu

                    JKnottJ 1 Reply Last reply Reply Quote 0
                    • JKnottJ Offline
                      JKnott @vallum
                      last edited by

                      @vallum said in Public networks behind firewall:

                      @jknott said in Public networks behind firewall:

                      @krisbe said in Public networks behind firewall:

                      I don't want to use NAT. Are there any other options then bridging?

                      Just turn off NAT, as described here.

                      how would that help?

                      The OPs question was "What is the best method to make them accessible from the internet? I don't want to use NAT. ". That means he wants a basic router, without NAT. So, the solution is to turn it off.

                      This is one thing that really bugs me about NAT. It's become so persuasive that many people think it's the normal way to do things. It's not. It's a hack to get around the IPv4 address shortage and creates some problems of it's own.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      1 Reply Last reply Reply Quote 0
                      • K Offline
                        Krisbe
                        last edited by

                        I think I found the answers here:

                        • https://docs.netgate.com/pfsense/en/latest/book/firewall/methods-of-using-additional-public-ip-addresses.html
                        • https://docs.netgate.com/pfsense/en/latest/book/routing/routing-public-ip-addresses.html

                        One more question. I want to use a few of these public IP's on devices on another pfSense interface. How can I do that?

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.