Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VIP Access From LAN

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    5 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      edinburgh1874
      last edited by

      Hi All,
      I have a few VIPs setup on my PFSense 2.1.5 FW, with 1:1 NAT setup to the internal IP addresses.

      DNS for these addresses works fine externally, however when a machine on the LAN address tries to access the WAN IP through HTTP/HTTPS I get the PFSense admin page (and a notice about DNS rebind attacks).

      I have manual NAT setup for the LAN addresses, and have tried "Enable NAT Reflection for 1:1 NAT".

      Does anyone have any idea how to get around this?

      Thanks

      1 Reply Last reply Reply Quote 0
      • M Offline
        mikeisfly
        last edited by

        You can turn off DNS rebind under system advance. Why not use the private IP they point to in your  network?

        1 Reply Last reply Reply Quote 0
        • E Offline
          edinburgh1874
          last edited by

          Thanks for the reply - that would just redirect to the PFSense admin page though.

          We host a lot of development/staging sites and they need to be accessible to developers on the LAN and customers externally through the same DNS name, which would be the WAN address.

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann
            last edited by

            It is a security risk to have the webconfigurator listen on WAN interface. You should change this.

            To access LAN hosts from another one in the LAN network by the external IP (DNS) you have to use "NAT reflection + proxy" mode, but this is not possible with 1:1 NAT.
            So to resolve your issue, you either have to change your NAT to port forward or use split DNS and configure an additional internal DNS server.

            1 Reply Last reply Reply Quote 0
            • E Offline
              edinburgh1874
              last edited by

              Thanks -  if I curl the WAN IP it's returning the internal address, I don't have any rules setup to allow the webconfigurator on the WAN port.

              Port forwarding + NAT Proxy appears to have worked, I didn't realise there is a difference with 1:1 NAT

              Thanks for your help!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.