• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to map LAN host to IP Alias for DNS resolution (let's encrypt)

Scheduled Pinned Locked Moved General pfSense Questions
8 Posts 4 Posters 604 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    pr0xyguy
    last edited by Jul 1, 2021, 1:18 AM

    hi guys,

    i have a pfsense with a single WAN + about 20 IP Alias.

    inbound traffic over the IP Alias's works fine using nat > port forward.

    however, i'm struggling with getting LAN traffic assigned to a specific IP Alias.

    issue - i'm trying to configure let's encrypt on an internal web server, but it (let's encrypt) keeps saying the IP of the host resolves to the WAN IP instead of the correct IP Alias.

    question - how can i configure a LAN host to work with a specific IP Alias?

    thanks.

    N K 2 Replies Last reply Jul 1, 2021, 2:38 AM Reply Quote 0
    • N
      NollipfSense @pr0xyguy
      last edited by NollipfSense Jul 4, 2021, 10:59 PM Jul 1, 2021, 2:38 AM

      @pr0xyguy I would start with turning off NAT on that IP.

      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

      1 Reply Last reply Reply Quote 0
      • K
        KOM @pr0xyguy
        last edited by Jul 1, 2021, 3:10 AM

        @pr0xyguy Instead of trying to fake out certbot, I think you should determine why it's complaining and fix that problem. Try to discover what certbot is looking up and what it's getting. Your server's hostname should not be it's public name. What's the the server's hosts file? What does your DNS have to say about that server?

        P 1 Reply Last reply Jul 1, 2021, 4:55 PM Reply Quote 0
        • P
          pr0xyguy @KOM
          last edited by pr0xyguy Jul 1, 2021, 4:55 PM Jul 1, 2021, 4:55 PM

          @kom

          the web server on LAN = 10.0.10.15

          i use external DNS (hover) which points the FQDN to 66.103.205.115 (for example) which is one of my IP Alias.

          when i run certbot on the 10.0.10.15 host, it resolves the domain name i'm trying to register fine - but the return packet is going over my pfsense's primary WAN and not the IP Alias the FQDN points to.

          so certbot keeps saying 'the domain xxx.com' resolves to a different IP address (the WAN and not the IP Alias).

          K 1 Reply Last reply Jul 1, 2021, 5:00 PM Reply Quote 0
          • K
            KOM @pr0xyguy
            last edited by Jul 1, 2021, 5:00 PM

            @pr0xyguy Create an Outbound NAT rule so that traffic initiated by the web server appears to be coming from the VIP.

            P 1 Reply Last reply Jul 1, 2021, 5:19 PM Reply Quote 1
            • P
              pr0xyguy @KOM
              last edited by pr0xyguy Jul 1, 2021, 5:20 PM Jul 1, 2021, 5:19 PM

              @kom

              so, i've looked at that, but when creating the outbound > NAT rule - for 'source' i can only choose 'Network / Any / This firewall (self)'

              shouldn't i set the 'source' to the LAN host IP (/.15)?

              thanks for the help btw.

              V 1 Reply Last reply Jul 1, 2021, 5:42 PM Reply Quote 0
              • V
                viragomann @pr0xyguy
                last edited by Jul 1, 2021, 5:42 PM

                @pr0xyguy
                If you want to set a rule for a single IP, select Network, enter the host IP and select a /32 mask.

                P 1 Reply Last reply Jul 1, 2021, 8:48 PM Reply Quote 1
                • P
                  pr0xyguy @viragomann
                  last edited by Jul 1, 2021, 8:48 PM

                  @viragomann

                  thanks brother, that worked.

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received