Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Email issue internal VLAN to LAN host

    General pfSense Questions
    2
    3
    60
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Dennis100 last edited by

      I have a web server on a VLAN. This is on a separate subnet/interface than the LAN. I'm trying to send emails to a LAN email host; web server (VLAN) -> VLAN interface -> WAN Interface -> NAT to LAN -> mail host. I can send emails from the VLAN web server to non local domains, EG gmail. However I cannot send emails to my local LAN email server. The LAN email server is a public facing system (working fine for sending/receiving emails). In the webhost logs I can see that it is trying to connect to the email server correctly (Public MX IP and port 25) but the connection just times out. I can ping the WAN IP from the web server successfully.
      The NAT setup for port 25 allows all WAN IPs to the mail host. I tried turning off blocking of private and bogon networks to no avail. Packet capture shows nothing. Ideas?

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Dennis100 last edited by

        @dennis100 said in Email issue internal VLAN to LAN host:

        web server (VLAN) -> VLAN interface -> WAN Interface -> NAT to LAN -> mail host.

        You mean, the mail server is accessed by its public IP, I guess?
        But the traffic never will pass the WAN interface, so the NAT rule is not applied to that traffic.

        Have you NAT reflection on in the NAT rule or have you a DNS override in place for the host name?

        D 1 Reply Last reply Reply Quote 1
        • D
          Dennis100 @viragomann last edited by

          Thanks for the hint. I didn't realize the traffic wouldn't pass the WAN interface. I'd forgotten that pfsense sort of acts like a router between interfaces by default. I blocked traffic between LAN & VLAN DMZ except for SMTP on the web server and set up a record in my hosts file so email could then be addressed to the mail host directly.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post

          Products

          • Platform Overview
          • TNSR
          • pfSense
          • Appliances

          Services

          • Training
          • Professional Services

          Support

          • Subscription Plans
          • Contact Support
          • Product Lifecycle
          • Documentation

          News

          • Media Coverage
          • Press
          • Events

          Resources

          • Blog
          • FAQ
          • Find a Partner
          • Resource Library
          • Security Information

          Company

          • About Us
          • Careers
          • Partners
          • Contact Us
          • Legal
          Our Mission

          We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

          Subscribe to our Newsletter

          Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

          © 2021 Rubicon Communications, LLC | Privacy Policy