Internal to external filtering?



  • Hi Y'all,

    We have a pfSense firewall set up (2.0-RC3), and have simple port forwarding on the WAN link to port forward to a LAN host.  It works great.  When hosts on the WAN (Internet) connect, they are port-forwarded correctly.

    However, hosts on the LAN (10.x.x.x) cannot hit WAN address and get port-forwarded back to the LAN correctly.  It appears those ports are filtered when coming from the LAN.

    Are there any ideas that jump out?  I've allowed RFC 1918 traffic to be allowed.  I can provide any other info if it would help…?

    Many thanks,
    erich



  • This is called NAT reflection and is turned off by default. You can enable that is System -> Advanced -> Firewall/NAT near the bottom of the page.

    Happy reflecting, but I would use split horizon (brain) DNS. Ends up being much faster.



  • Gravy!  Works like a charm, thanks for the terminology lesson.  ;)


Log in to reply