OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [Solved] Accessing an internal webserver
« previous next »
  • Print
Pages: [1]

Author Topic: [Solved] Accessing an internal webserver  (Read 24558 times)

jl_678

  • Newbie
  • *
  • Posts: 14
  • Karma: 0
    • View Profile
[Solved] Accessing an internal webserver
« on: November 12, 2017, 10:50:55 pm »
Update: See last post for the simple solution

Hi,

I just installed Opnsense and things are working well.  However, I have encountered an unexpected issue.  Here is what I am seeing:

I used named-based web-hosting and so my external hostname is both foo.bar.com and foo2.bar.com.  These go to the same server and Apache uses the DNS to send me to the right site and SSL is in use.

If I am on an external network, I can access foo2.bar.com without an issue.  This is through port 443 and https, and I have a rule setup allowing access to an internal server say 10.0.0.20.

The problem occurs if I am on my internal network.  Now, let's say that I want to access the foo2.bar.com SSL site on 10.0.0.20.  The first thing that I try is to go to foo2.bar.com.  However, this does not work.  I think that the problem is due to DNS resolving the public IP and then Opnsense trying to send the GUI which creates an error.  Going to https://10.0.0.20 does not work because it provides the foo.bar.com website and not foo2.bar.com.

I tried changing the GUI to a different port and now the internal requests to foo2.bar.com time out.  What can I do to enable access to foo2.bar.com?

Thank you!
« Last Edit: November 14, 2017, 03:52:42 am by jl_678 »
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 1604
  • Karma: 167
    • View Profile
Re: Accessing an internal webserver
« Reply #1 on: November 13, 2017, 08:23:23 am »
Run an internal DNS server and provide split DNS https://en.wikipedia.org/wiki/Split-horizon_DNS

Bart...
Logged

jl_678

  • Newbie
  • *
  • Posts: 14
  • Karma: 0
    • View Profile
Re: Accessing an internal webserver
« Reply #2 on: November 13, 2017, 05:17:03 pm »
Okay, I will explore that.  Thank you. 

For future reference, I created a temporary workaround.  Specifically, I enabled port-based web-hosting for foo2.bar.com.  In this scenario, I created another vHost inside of Apache and set foo2.bar.com to be accessible by going to https://10.0.0.20:8080.

This is not the ideal solution and is a bit of a hack.  I will look at the internal DNS server option.

Thank you.
Logged

BertM

  • Jr. Member
  • **
  • Posts: 53
  • Karma: 11
    • View Profile
Re: Accessing an internal webserver
« Reply #3 on: November 13, 2017, 05:47:42 pm »
jl_678

No need to use internal DNS server.
The trick is to use NAT reflection in your port forwarding config.

See description in this post:
https://forum.opnsense.org/index.php?topic=6155

Kind regards,
Bert
Logged

jl_678

  • Newbie
  • *
  • Posts: 14
  • Karma: 0
    • View Profile
Re: Accessing an internal webserver
« Reply #4 on: November 14, 2017, 03:14:55 am »
Unfortunately, the NAT reflector thing did not work for me. I have no idea why. I posted on that thread.
Logged

jl_678

  • Newbie
  • *
  • Posts: 14
  • Karma: 0
    • View Profile
[SOLVED]Re: Accessing an internal webserver
« Reply #5 on: November 14, 2017, 03:52:09 am »
Hi,

So I was exploring the dual DNS thing and it was really easy to implement.  You simply go to your DNS settings (either DNS Masq or Unbound) and set an override for the internal webserver.  In my example, it looked something like this:

host: foo2
domain: bar.com
(for Unbound) -> Type A
IP: 10.0.0.20

With those settings, it worked perfectly and there was no need to change the GUI port or anything.
Logged

Deku2

  • Newbie
  • *
  • Posts: 29
  • Karma: 1
    • View Profile
Re: [Solved] Accessing an internal webserver
« Reply #6 on: June 26, 2018, 09:15:02 pm »
Didn't work for me as it doesn't do the port forwarding aspect.  Can't figure out how to access my site from inside  :( 
This didn't work either: https://forum.opnsense.org/index.php?topic=6155.0
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [Solved] Accessing an internal webserver
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2