nat reflection from lan to dmz

Started by miguel.mirandag, December 08, 2019, 03:11:51 PM

Previous topic - Next topic
Hi, i have migrated from a fortigate utm to opnsense, i am very impressed with the look and feel and overall easy configuration.
Howerver i am facing a problem that a did not have before with fortigate fw, my topology is very simple:

internet -> core router -> opnsense

opnsense has 3 interfaces: wan, lan and dmz (renamed from opt1), in dmz  i have a plesk panel running a mail/web server i also have an iptv middleware server, both using rfc1819 networks being nated by opnsense. For several factors that i can not change right now i have a mobile appication that uses iptv's server public ip to connect to the middleware system,
Nat is working fine from the outside (public internet), i have enable globally the nat reflection for port forward settings, if i connecto to the iptv server from dmz network all is working fine, so the nat reflection is working into dmz network, this is not happening if i connect to iptv server from lan natwork,  there is a timeout and if i run a tracert command the packet goes to public internet via wan connection instead of redirect me to the internal iptv server in dmz network. split horizon won't help me here beacuse the application is configured internally to use public ip address , not by fqdn.
How can i make this configuration? Am i missing somethng, maybe a redirect rule, if so where do i have to configure it, in out nat or in lan interface?