<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Problem with maiserver moved from lan to dmz]]></title><description><![CDATA[<p dir="auto">Hi all</p>
<p dir="auto">I moved a mailserver from the lan to the dmz and I am having some troubles.</p>
<p dir="auto">LAN B–------ ipsec -----router-vpn--------LAN A-----------FIREWALL  -----internet<br />
192.168.2/24                    192.168.1.254    192.168.1/24      192.168.1.251  ---- dmz  (192.168.100/24) - mailserver</p>
<p dir="auto">From the lanA subnet (192.168.1/24) is't all ok<br />
But from the remote lan (192.168.2/24) (connected via an ipsec tunnel between two cisco routers) connections to the mailserver (192.168.100.2) are very slow and clients like imapclients give random errors.<br />
The ipsec tunnel is 192.168.2/24 &gt; any and any &gt; 192.168.2/24<br />
In the firewall there is a static route to 192.168.2/24 via 192.168.1.254<br />
from LANB clients I can do telnet dmz:ports (25-80-143) but I receive answer after some seconds<br />
I test the system with a pass all in the lan and in the dmz</p>
<p dir="auto">what can I check ?<br />
thanks<br />
Giacomo</p>
]]></description><link>https://forum.netgate.com/topic/6641/problem-with-maiserver-moved-from-lan-to-dmz</link><generator>RSS for Node</generator><lastBuildDate>Thu, 18 Jun 2026 14:49:03 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/6641.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 06 Dec 2007 00:42:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Problem with maiserver moved from lan to dmz on Thu, 06 Dec 2007 15:41:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/sylhouette">@<bdi>Sylhouette</bdi></a>:</p>
<blockquote>
<p dir="auto">did you check the box in system –&gt; advanced --&gt;  Static route filtering, you need to do so.</p>
<p dir="auto">regards,<br />
Johan</p>
</blockquote>
<p dir="auto">Yes it's checked.</p>
<p dir="auto">Giacomo</p>
]]></description><link>https://forum.netgate.com/post/162848</link><guid isPermaLink="true">https://forum.netgate.com/post/162848</guid><dc:creator><![CDATA[capitangiaco]]></dc:creator><pubDate>Thu, 06 Dec 2007 15:41:31 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with maiserver moved from lan to dmz on Thu, 06 Dec 2007 11:15:30 GMT]]></title><description><![CDATA[<p dir="auto">did you check the box in system –&gt; advanced --&gt;  Static route filtering, you need to do so.</p>
<p dir="auto">regards,<br />
Johan</p>
]]></description><link>https://forum.netgate.com/post/162831</link><guid isPermaLink="true">https://forum.netgate.com/post/162831</guid><dc:creator><![CDATA[Sylhouette]]></dc:creator><pubDate>Thu, 06 Dec 2007 11:15:30 GMT</pubDate></item></channel></rss>