• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

ISP access provider router which allows port 80 redirect on an apache web server which is online on the web.

Scheduled Pinned Locked Moved Traffic Shaping
5 Posts 2 Posters 448 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    Arnaud09
    last edited by Oct 15, 2020, 8:43 PM

    Hello.

    The subject relates to putting the web server online and not the private network.

    Here I configured my ISP access provider router which allows port 80 redirection on an apache web server which is online on the web.
    In other words, I put two web servers and a DNS server online from my home by authorizing a redirection of my internet router from port 80.

    All of them are working fine. This network is called 'web-service' and is accessible from a domain name over the net.

    I have since acquired a pfsense router to protect precisely this 'service-web' network.

    My question is whether I should protect my 'service-web' network with pfsense?
    If so, should I put my 'service-web' machines on the WAN or the LAN?

    Thanks a lot.

    A 1 Reply Last reply Oct 18, 2020, 8:19 AM Reply Quote 0
    • A
      Arnaud09 @Arnaud09
      last edited by Arnaud09 Oct 18, 2020, 8:20 AM Oct 18, 2020, 8:19 AM

      @Arnaud09 said in ISP access provider router which allows port 80 redirect on an apache web server which is online on the web.:

      should I put my 'service-web' machines on the WAN or the LAN?

      I believe both are possible. Would it have a tutorial from this forum?

      Thanks

      B 1 Reply Last reply Oct 18, 2020, 8:32 AM Reply Quote 0
      • B
        bingo600 @Arnaud09
        last edited by Oct 18, 2020, 8:32 AM

        @Arnaud09

        Will you still have the ISP router with portforwarding active ?
        Or will the pfSense take over the Public ip address (and the router function)

        If you find my answer useful - Please give the post a 👍 - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

        A 1 Reply Last reply Oct 18, 2020, 12:32 PM Reply Quote 0
        • A
          Arnaud09 @bingo600
          last edited by Oct 18, 2020, 12:32 PM

          @bingo600 said in ISP access provider router which allows port 80 redirect on an apache web server which is online on the web.:

          @Arnaud09

          Will you still have the ISP router with portforwarding active ?
          Or will the pfSense take over the Public ip address (and the router function)

          I have the ISP router with portforwarding active.

          Thank you for your reply

          B 1 Reply Last reply Oct 18, 2020, 12:43 PM Reply Quote 0
          • B
            bingo600 @Arnaud09
            last edited by bingo600 Oct 18, 2020, 1:02 PM Oct 18, 2020, 12:43 PM

            @Arnaud09

            Assumption:
            You portforward those 3 services, each to their own isp inside lan ip ?

            Then i would put the pfSense wan on your isp routers inside lan on (fixed) ip addr xxx ... Don't use DHCP , and remember to set default gw on the pfsense to your routers inside ip address.

            And "portforward" the wanted ports on your isp router, to the routers inside lan on ip addr xxx (the pfSense wan ip).

            Now matching (portforwarded) traffic will hit the pfSense Wan interface.

            Then you need to do the same portforwarding once more on the pfSense , to portforward the interesting stuff on the WAN to the LAN.

            Now you can control access to the pfSense LAN (that would be your service lan) , by putting access rules on your pfSense wan interface (preventing unwanted packages from entering the WAN .. And thereby access the Lan.

            Be sure that your ISP router inside lan , and your pfSense inside lan does not have the same ip range or it will never work.

            I might have given multiple VIP's a try .. Haven't used those yet.
            But that might not be easy for a "Non experienced person"

            If you are able to add routes to your ISP Router , things might become a lot easier.

            /Bingo

            If you find my answer useful - Please give the post a 👍 - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received