Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
17.7 Legacy Series
»
[Solved] Accessing an internal webserver
« previous
next »
Print
Pages: [
1
]
Author
Topic: [Solved] Accessing an internal webserver (Read 36951 times)
jl_678
Newbie
Posts: 14
Karma: 0
[Solved] Accessing an internal webserver
«
on:
November 12, 2017, 10:50:55 pm »
Update: See last post for the simple solution
Hi,
I just installed Opnsense and things are working well. However, I have encountered an unexpected issue. Here is what I am seeing:
I used named-based web-hosting and so my external hostname is both foo.bar.com and foo2.bar.com. These go to the same server and Apache uses the DNS to send me to the right site and SSL is in use.
If I am on an external network, I can access foo2.bar.com without an issue. This is through port 443 and https, and I have a rule setup allowing access to an internal server say 10.0.0.20.
The problem occurs if I am on my internal network. Now, let's say that I want to access the foo2.bar.com SSL site on 10.0.0.20. The first thing that I try is to go to foo2.bar.com. However, this does not work. I think that the problem is due to DNS resolving the public IP and then Opnsense trying to send the GUI which creates an error. Going to
https://10.0.0.20
does not work because it provides the foo.bar.com website and not foo2.bar.com.
I tried changing the GUI to a different port and now the internal requests to foo2.bar.com time out. What can I do to enable access to foo2.bar.com?
Thank you!
«
Last Edit: November 14, 2017, 03:52:42 am by jl_678
»
Logged
bartjsmit
Hero Member
Posts: 1999
Karma: 193
Re: Accessing an internal webserver
«
Reply #1 on:
November 13, 2017, 08:23:23 am »
Run an internal DNS server and provide split DNS
https://en.wikipedia.org/wiki/Split-horizon_DNS
Bart...
Logged
jl_678
Newbie
Posts: 14
Karma: 0
Re: Accessing an internal webserver
«
Reply #2 on:
November 13, 2017, 05:17:03 pm »
Okay, I will explore that. Thank you.
For future reference, I created a temporary workaround. Specifically, I enabled port-based web-hosting for foo2.bar.com. In this scenario, I created another vHost inside of Apache and set foo2.bar.com to be accessible by going to
https://10.0.0.20:8080
.
This is not the ideal solution and is a bit of a hack. I will look at the internal DNS server option.
Thank you.
Logged
BertM
Jr. Member
Posts: 53
Karma: 12
Re: Accessing an internal webserver
«
Reply #3 on:
November 13, 2017, 05:47:42 pm »
jl_678
No need to use internal DNS server.
The trick is to use NAT reflection in your port forwarding config.
See description in this post:
https://forum.opnsense.org/index.php?topic=6155
Kind regards,
Bert
Logged
jl_678
Newbie
Posts: 14
Karma: 0
Re: Accessing an internal webserver
«
Reply #4 on:
November 14, 2017, 03:14:55 am »
Unfortunately, the NAT reflector thing did not work for me. I have no idea why. I posted on that thread.
Logged
jl_678
Newbie
Posts: 14
Karma: 0
[SOLVED]Re: Accessing an internal webserver
«
Reply #5 on:
November 14, 2017, 03:52:09 am »
Hi,
So I was exploring the dual DNS thing and it was really easy to implement. You simply go to your DNS settings (either DNS Masq or Unbound) and set an override for the internal webserver. In my example, it looked something like this:
host: foo2
domain: bar.com
(for Unbound) -> Type A
IP: 10.0.0.20
With those settings, it worked perfectly and there was no need to change the GUI port or anything.
Logged
Deku2
Newbie
Posts: 30
Karma: 1
Re: [Solved] Accessing an internal webserver
«
Reply #6 on:
June 26, 2018, 09:15:02 pm »
Didn't work for me as it doesn't do the port forwarding aspect. Can't figure out how to access my site from inside
This didn't work either:
https://forum.opnsense.org/index.php?topic=6155.0
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
17.7 Legacy Series
»
[Solved] Accessing an internal webserver