Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Setup and understanding Port Forwarding, also Exchange

    Scheduled Pinned Locked Moved NAT
    3 Posts 3 Posters 438 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rylen
      last edited by

      I'm new to pfSense and it has a lot more things to configure than I'm used to.

      My setup:
      Internet facing ISP provided cable modem.
      pfSense SG-1100 router.
      Windows AD server doing DHCP, DNS, etc.
      Exchange Server named Exchange01.
      3CX Server

      On past routers, I've set up a port forwarding rule to send ports 25, 80, 443, and 997 to Exchange01.
      I've done that here and it works with Outlook Web Access (OWA) for computers on the internet but I get either a 404 error or "possible DNS binding attack" error when I try to reach OWA and ECP from a computer on the local network.

      My current rules are formatted:
      Dest Addr: WAN
      Dest Port: 25
      Nat IP: ....1.11
      Nat Port: 25

      For my 3CX server, I have outbound NAT in a hybrid mode. I don't see this mattering, but I've been wrong about what is relevant before.

      I think I'm supposed to use either NAT Reflection or Split DNS to fix this. I'm not sure which is more appropriate.

      https://docs.netgate.com/pfsense/en/latest/nat/accessing-port-forwards-from-local-networks.html

      Which should I use here? Or is my problem likely something else?

      Thanks you,
      Rylen

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Split DNS would be best practice here.

        1 Reply Last reply Reply Quote 0
        • kiokomanK
          kiokoman LAYER 8
          last edited by

          yup split dns
          https://docs.netgate.com/pfsense/en/latest/nat/accessing-port-forwards-from-local-networks.html#method-2-split-dns

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.