subdomains / haproxy not working on lan, working on wan

Started by kasperski1868, January 20, 2026, 01:27:22 PM

Previous topic - Next topic
So after a lot of fidgeting I got my synology apps and some docker applications wan-accessible through subdomains (on a cloudflare domain) with ACME/haproxy/unboundDNS in Opnsense. It worked both from lan and wan initially, but recently I discovered that now it only works from wan. Changes I' ve made recently are DNS through PiHole instance (proxmox) which I have already reverted back to the IP of the router, and a couple of Opnsense updates.

To anyones knowledge: could my (quite possibly imperfect) setup now be failing because of recent Opnsense changes? 

Do all your subdomains resolve properly to the OPNsense interface, which HAproxy is listening on?

Best to have to internal DNS overrides for the domains. So they are resolved to the WAN address. This assumes, that you have your public address assigned to OPNsense, however.

Found the issue: I installed crowdsec recently .. this seems to be the culprit. Guess I' ll have to learn some more about that one before I turn it on again. Thanks!

You need to whitelist your internal addresses.

Either with this parser:

https://app.crowdsec.net/hub/author/crowdsecurity/log-parsers/whitelists

or manually following the documentation:

https://doc.crowdsec.net/u/getting_started/post_installation/whitelists/
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)