Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    nat for 2 email servers with just 1 wan?

    NAT
    5
    12
    72
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • periko
      periko last edited by

      Hi guys.

      I have 2 email servers for different domains.

      1 pfsense with 1 wan.

      Is possible to NAT traffic for both servers using the same email ports 465/993 on each one?

      Or is possible to deal with something like this?

      Thanks for your time.

      Gertjan 1 Reply Last reply Reply Quote 0
      • KOM
        KOM last edited by

        Not that I'm aware of. You could possibly arrange for another public IP address from your ISP, and then add that as a VIP. Then you could create NAT rules to handle both servers.

        periko 1 Reply Last reply Reply Quote 0
        • Grimson
          Grimson Banned last edited by

          You can have 1 mail server in front accept mails for both domains, and then if separation is required forward the mails to the actual mail server for each domain.

          This can not be solved by NAT.

          periko 1 Reply Last reply Reply Quote 0
          • Rico
            Rico LAYER 8 Rebel Alliance last edited by

            Never tried it but should be possible with HAProxy.

            -Rico

            Grimson 1 Reply Last reply Reply Quote 0
            • periko
              periko @Grimson last edited by

              @grimson u mean add a extra email server that will accept the connection and them forward the traffic base on something to email1 or email2 ?

              1 Reply Last reply Reply Quote 0
              • periko
                periko @KOM last edited by

                @kom here with scenario we need 2 wans to manage the traffic for each email server right?

                KOM 1 Reply Last reply Reply Quote 0
                • Rico
                  Rico LAYER 8 Rebel Alliance last edited by

                  No, if your ISP can route multiple IPs to you say they give you a /30 or /29 network all can be handled with one WAN interface.

                  -Rico

                  periko 1 Reply Last reply Reply Quote 0
                  • Grimson
                    Grimson Banned @Rico last edited by Grimson

                    @rico said in nat for 2 email servers with just 1 wan?:

                    Never tried it but should be possible with HAProxy.

                    I've only seen HAProxy for load-balancing purposes on mail servers, not to distribute the mails to different servers based on the sender/receiver address.

                    @periko said in nat for 2 email servers with just 1 wan?:

                    @grimson u mean add a extra email server that will accept the connection and them forward the traffic base on something to email1 or email2 ?

                    https://en.wikipedia.org/wiki/SMTP_proxy

                    1 Reply Last reply Reply Quote 0
                    • periko
                      periko @Rico last edited by

                      @rico can u please give more details in case we have other IP available and want to use the VIP u mention?👂

                      1 Reply Last reply Reply Quote 0
                      • KOM
                        KOM @periko last edited by

                        @periko Call your ISP and ask them how much it would cost for them to assign & route to you another IP address. It should be no problem if it is a business account. Then you simply add it to pfSense as a Virtual IP - IP Alias.

                        periko 1 Reply Last reply Reply Quote 0
                        • periko
                          periko @KOM last edited by

                          @kom I will check this, thanks.

                          1 Reply Last reply Reply Quote 0
                          • Gertjan
                            Gertjan @periko last edited by

                            @periko said in nat for 2 email servers with just 1 wan?:

                            Is possible to NAT traffic for both servers using the same email ports 465/993 on each one?

                            These are ports to deposit mail for sending (smtps) and consulting mails on a mailbox/server imaps (993).

                            These two ports are probably used by fat-mail-clients like Outlook or Thunderbird.
                            Take the more intelligent (smaller ?) user (== domain ?) group of your 2 mail servers, and say to these guys : "Hey, guys, if you see somewhere that mentions port '993', change it for 994' - idem for 465, make that 466."
                            Now you can NAT easily on your side.

                            Most people don't care less what they have to choose, they only setup a mail clients ones, and will redo it when their computer breaks down after X years. They don't know why its "465" or "993" anyway.

                            Note : this won't work if it concerns port 80 or 443 .... people don't know that they use these ports several times a day

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post

                            Products

                            • Platform Overview
                            • TNSR
                            • pfSense
                            • Appliances

                            Services

                            • Training
                            • Professional Services

                            Support

                            • Subscription Plans
                            • Contact Support
                            • Product Lifecycle
                            • Documentation

                            News

                            • Media Coverage
                            • Press
                            • Events

                            Resources

                            • Blog
                            • FAQ
                            • Find a Partner
                            • Resource Library
                            • Security Information

                            Company

                            • About Us
                            • Careers
                            • Partners
                            • Contact Us
                            • Legal
                            Our Mission

                            We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                            Subscribe to our Newsletter

                            Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                            © 2021 Rubicon Communications, LLC | Privacy Policy