OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • virtual IP en Nat 1:1
« previous next »
  • Print
Pages: [1]

Author Topic: virtual IP en Nat 1:1  (Read 3512 times)

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
virtual IP en Nat 1:1
« on: October 13, 2017, 12:26:40 am »
Dear All,
We are using Opnsense facing the Internet with 3 Virtual WAN IP. the below IP addresses are just a example.

4.100.23.9/13

so the WAN IP is 4.100.23.9
Virtual IP are 4.100.23.10,4.100.23.12 and 4.100.23.13

on the WAN we have NAT the ports to 443 and 80 to the exchange server which is behind the LAN
now we have added the Virtual IP as IP and WAN and created a NAT 1:1 to forward the IP 4.100.23.10 to the internet Filter which is on the LAN.

so on the internet side when we access the https://4.100.23.10 its opens the Exchange server which is behind the 4.100.23.9.

Can someone please advise how to get this correctly configured ?


« Last Edit: October 13, 2017, 12:38:44 am by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: virtual IP en Nat 1:1
« Reply #1 on: October 13, 2017, 12:39:28 am »
I managed to get this fixing,
had to remove the NAT ports on the WAN interface.
and do 1:1 NAT
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: virtual IP en Nat 1:1
« Reply #2 on: October 13, 2017, 09:49:19 am »
Hi Guys,
After adding the virtual IP the open VPN has stopped working ( handshake failed ).
the rule on the WAN
Port IPV4 UDP Source * Port * Destinational WAN Address Port 1194 does not works anymore.
I've noticed if we remove the 1:1 Nat rules on the Firewall VPN start working.


Can someone please advise what am I doing wrong ?



« Last Edit: October 13, 2017, 12:47:50 pm by Julien »
Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

Julien

  • Hero Member
  • *****
  • Posts: 651
  • Karma: 32
    • View Profile
Re: virtual IP en Nat 1:1
« Reply #3 on: October 14, 2017, 04:57:47 pm »
up guys,
anyone has een idea please ?

Logged
An intelligent man is sometimes forced to be drunk to spend time with his fool.

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • virtual IP en Nat 1:1
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2