Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
21.7 Legacy Series
»
Forward SMTP from Internet to LAN using IPSec
« previous
next »
Print
Pages: [
1
]
Author
Topic: Forward SMTP from Internet to LAN using IPSec (Read 3094 times)
Sascha79
Newbie
Posts: 5
Karma: 0
Forward SMTP from Internet to LAN using IPSec
«
on:
November 23, 2021, 12:24:57 pm »
Hi!
I have OPNsense (21.7.5) running on a machine having an public (static) IP.
Now I'd like to forward incoming SMTP to my private mailserver in my home-network which is connected using IPsec like:
Internet -> Public-IP:25 -> NAT -> IPSec -> Private Mailserver
Traffic from OPNsense flows fine through IPSec-Tunnel.
Unfortunately, the Port Forward from WAN-Address:25 to the LAN-Address of my mailserver does not work.
Can anybody give me a tip how to set it up?
Edit:
* Port Probe using Source Address "LAN" to Mailserver works fine.
* Port Probe using "WAN" to Mailserver does not work.
Thanks!
Sascha
«
Last Edit: November 23, 2021, 12:40:21 pm by Sascha79
»
Logged
Sascha79
Newbie
Posts: 5
Karma: 0
Re: Forward SMTP from Internet to LAN using IPSec
«
Reply #1 on:
November 24, 2021, 07:49:36 pm »
Did nobody ever try this with OPNsense?
Logged
schnipp
Sr. Member
Posts: 371
Karma: 19
Re: Forward SMTP from Internet to LAN using IPSec
«
Reply #2 on:
November 24, 2021, 08:23:58 pm »
Can you explain in more detail what you try to achieve? Do I understand correctly that you have an IPsec tunnel with Opnsense and the mail server as two tunnel endpoints? What's the reason for it?
Additionally, please post relevant firewall and dnat rules as well as the IPsec configuration.
Logged
OPNsense 24.7.1-amd64
Sascha79
Newbie
Posts: 5
Karma: 0
Re: Forward SMTP from Internet to LAN using IPSec
«
Reply #3 on:
November 25, 2021, 04:48:39 pm »
OPNsense is running at gridscale (an IaaS-Provider) and can get a static IPs from there.
It has two NICs: WAN and LAN.
(Reason for all this: at home, there's no static IP and therefore I'd like to send E-Mail through the tunnel.)
The only setting is a Port Forward matching WAN address at Port 25 natting to the IP on the other side of the tunnel.
A strange thing is: I can ping the private IP from OPNsense using it's LAN-Address but not using the WAN-Address?!
Logged
schnipp
Sr. Member
Posts: 371
Karma: 19
Re: Forward SMTP from Internet to LAN using IPSec
«
Reply #4 on:
November 25, 2021, 05:11:03 pm »
There are still not enough information to help you. Additionally, to the already requested information can please provide us with an architecture overview and do the following checks:
Check whether there is a firewall active on your private mail server
Check whether you can establish a TCP (e.g. telnet) connection from Opnsense to your private mail server
Check whether you can establish a TCP (e.g. telnet) connection from the Internet to your private mail server
Logged
OPNsense 24.7.1-amd64
Sascha79
Newbie
Posts: 5
Karma: 0
Re: Forward SMTP from Internet to LAN using IPSec
«
Reply #5 on:
November 25, 2021, 05:54:25 pm »
There's really not much architecture - just the OPNsense-box at the remote location - it's one end of the IPSec-Tunnel. The other end of the tunnel is a MikroTik-Router (CCR2004 if it helps) connecting it to the private LAN where the mailserver sits. Firewall is completely open for IPSec.
I'm testing connection using OPNsense > Interfaces > Diagnostics > Port Probe
OPNsense succeeds opening connection to the mailserver if the LAN-NIC is selected as Source Address.
If WAN is selected, it says nc: connect to xxx.xxx.xxx.xxx port 25 (tcp) failed: Operation timed out
Logged
schnipp
Sr. Member
Posts: 371
Karma: 19
Re: Forward SMTP from Internet to LAN using IPSec
«
Reply #6 on:
November 26, 2021, 04:24:44 pm »
It looks like your NAT, firewall, IPsec tunnel or mailserver is not properly configured. Without details it's like looking in a crystal ball.
BTW, in my eyes it's risky to forward internet mail traffic to a SMTP server within your LAN. If something breaks at the application layer an attacker might have access to you LAN environment. Furthermore, in case the IPsec tunnel covers the whole LAN subnet an there is no additional firewall in local LAN segment you have to trust your hoster and its security controls. It's better to have the internet connected mail server in the DMZ and only forward appropriate mails to your local LAN mailboxes.
Logged
OPNsense 24.7.1-amd64
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
21.7 Legacy Series
»
Forward SMTP from Internet to LAN using IPSec