OPNsense Forum

Archive => 16.7 Legacy Series => Topic started by: kdmiller45 on January 03, 2017, 01:24:40 am

Title: Server setup behind a OPNsense firewall
Post by: kdmiller45 on January 03, 2017, 01:24:40 am
what does the network setup look like for servers behind the firewall to enable packet forwarding to a static IP
Title: Re: Server setup behind a OPNsense firewall
Post by: deviantintegral on January 03, 2017, 02:06:48 am
I just set up a port forward, though there were a few nuances to it.

For managing the IPs and addresses, assign a static IP to the server (I did a static DHCP assignment). Then, if you create an alias for it, you can easily change the IP later without having to update a bunch of firewall rules (love this!).

The destination needs to be set to WAN, and not the server you are forwarding to. It's the Redirect IP / Port rules you use for the server mapping. Also, there are settings for the Admin GUI that control the port it's listening on. You may need to move it if by "site" you mean a literal web server that you're forwarding to.
Title: Re: Server setup behind a OPNsense firewall
Post by: kdmiller45 on January 03, 2017, 02:32:38 am
I have my server properties setup for a static IP 192.168.1.120 I duplicated the DNS settings that are given to OPNsense

attached are my setup Aliases and Port forwarding
and the client still times out trying to connect to the web server
Title: Re: Server setup behind a OPNsense firewall
Post by: fabian on January 03, 2017, 01:03:17 pm
There are some things I would look at:

* Is your client coming from WAN (otherwise the rule will not be triggered)
* Does your client reach the firewall (provider does NAT etc.)
Title: Re: Server setup behind a OPNsense firewall
Post by: kdmiller45 on January 03, 2017, 01:46:38 pm
My server is behind the OPNsense firewall (192.168.1.120), the client attempting to connect is a hotspot on my cell with WiFi turned off.

I can Ping the server from within the network (Behind firewall) but not outside,
as a note I had port forwarding setup on the router working fine, but something is configured wrong on OPNsense

All workstations/Server can browse the internet
Title: Re: Server setup behind a OPNsense firewall
Post by: bartjsmit on January 03, 2017, 05:04:22 pm
Ping requires a separate firewall rule. Does the web site work?
Title: Re: Server setup behind a OPNsense firewall
Post by: kdmiller45 on January 03, 2017, 05:24:52 pm
No it does not working at all
Prior to OPNsense It worked via Internet and by using IIS right click on domain, select browse and it opened up in IE.
Title: Re: Server setup behind a OPNsense firewall
Post by: bartjsmit on January 04, 2017, 08:21:29 am
If your website won't even respond on the internal network, you should fix that first. Is the Windows WWW publishing service running? Any events?