Setup and understanding Port Forwarding, also Exchange
-
I'm new to pfSense and it has a lot more things to configure than I'm used to.
My setup:
Internet facing ISP provided cable modem.
pfSense SG-1100 router.
Windows AD server doing DHCP, DNS, etc.
Exchange Server named Exchange01.
3CX ServerOn past routers, I've set up a port forwarding rule to send ports 25, 80, 443, and 997 to Exchange01.
I've done that here and it works with Outlook Web Access (OWA) for computers on the internet but I get either a 404 error or "possible DNS binding attack" error when I try to reach OWA and ECP from a computer on the local network.My current rules are formatted:
Dest Addr: WAN
Dest Port: 25
Nat IP: ....1.11
Nat Port: 25For my 3CX server, I have outbound NAT in a hybrid mode. I don't see this mattering, but I've been wrong about what is relevant before.
I think I'm supposed to use either NAT Reflection or Split DNS to fix this. I'm not sure which is more appropriate.
https://docs.netgate.com/pfsense/en/latest/nat/accessing-port-forwards-from-local-networks.html
Which should I use here? Or is my problem likely something else?
Thanks you,
Rylen -
Split DNS would be best practice here.
-
yup split dns
https://docs.netgate.com/pfsense/en/latest/nat/accessing-port-forwards-from-local-networks.html#method-2-split-dns