• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

server certificate problem

Scheduled Pinned Locked Moved General pfSense Questions
5 Posts 3 Posters 608 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • А
    Андрей85
    last edited by Андрей85 Sep 13, 2020, 10:51 PM Sep 13, 2020, 10:48 PM

    Hello. I ran into the problem of determining the certificate by the browser. I will explain everything in order. I have two servers: one running Nextcloud, the other running Proxmox + pfSense. Some time ago I only used one pfSense on the second server. A certificate was obtained for the Nextcloud server from LetsEncrypt and installed successfully. My cloud worked great both internally and externally. As soon as I installed pfSense on the virtual machine, access from the local network (I tried both single-net and different subnets) to the cloud stopped: the browser swears about the mismatch of the certificate, which turned out to be self-signed from pfSense. With external access to Nexcloud, there is no such problem with the certificate. Help me solve the problem, please.

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Sep 13, 2020, 11:51 PM

      Access the server via its local IP, just setup a host override to resolve the fqdn to the local IP vs trying to do nat reflection. Which you would have to setup if you want to go that route, but the host override is better choice.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • А
        Андрей85
        last edited by Sep 14, 2020, 5:55 AM

        Thanks for the answer, but I don't understand something. I created a rule for Nat, port forwarding. I tried to ping the server using fqdn from the local host and see the local address of the server. From the browser, I can see the server both by the local ip and by the full name. But only the certificate is different, not the one installed on the server. Does the router change the certificate when processing a packet? At first glance, it is.

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by Sep 14, 2020, 12:04 PM

          If you are hitting the pfSense self-signed cert when testing internally you need to do one of this things shown here:

          https://docs.netgate.com/pfsense/en/latest/nat/accessing-port-forwards-from-local-networks.html

          Steve

          А 1 Reply Last reply Sep 14, 2020, 4:52 PM Reply Quote 1
          • А
            Андрей85 @stephenw10
            last edited by Sep 14, 2020, 4:52 PM

            @stephenw10 , Thank you very much for the direction to the necessary information. According to the documentation on the link, I configured DNS forvarder properly, rechecked the settings of all hosts. Oh, miracle !!! Some had a DNS server 8.8.8.8. I fixed it and it worked. Thank you very much for your support!

            1 Reply Last reply Reply Quote 1
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received