OPNsense Forum

Archive => 23.1 Legacy Series => Topic started by: Paddle7306 on June 22, 2023, 04:08:58 AM

Title: Reverse proxy doesn't work when on LAN, only WAN
Post by: Paddle7306 on June 22, 2023, 04:08:58 AM
I've got a working OPNsense VM running but I'm having trouble with my Synology reverse proxy. This was working well with my Asus RT-AX89X router so I assume I have as setting wrong with OPNsense. Here's what I know:

What have I set wrong? I considered maybe I needed port forwards for LAN and WAN but I didn't want to start changing things and risk taking the work-from-home router offline... again.
Title: Re: Reverse proxy doesn't work when on LAN, only WAN
Post by: bartjsmit on June 22, 2023, 08:39:03 AM
Do you have NAT reflection set on the firewall rule? The most secure is to use split DNS between internal and external clients but that is a bit more involved.
Title: Re: Reverse proxy doesn't work when on LAN, only WAN
Post by: Paddle7306 on June 23, 2023, 04:09:06 AM
If you're asking if I turned on "Reflection for port forwards" in Firewall > Settings > Advanced, I didn't have it set but after turning that on it didn't work any differently. It didn't seem to create any news rules under NAT but maybe I have to create rules after enabling that setting.
Title: Re: Reverse proxy doesn't work when on LAN, only WAN
Post by: JamesFrisch on June 23, 2023, 07:07:53 AM
I personally solve that problem by setting a DNS override for A records. AAAA records are fine, because they are the same external or internal. My DNS override points to the 192.168.1.10 local IP of the reverse proxy instead of the 80.80.80.80 WAN IP that public resolver gets.