WAN /29 network; port fwd for intl. server coming in at specific IP address?

Started by atoll, June 25, 2022, 04:24:14 PM

Previous topic - Next topic
Hi,

my OPNsense 22.1.8 connects to the internet per WAN interface via a /29 network, fixed addresses.

Let's call the network 56.142.3.73/29, where 56.142.3.73 is the uplink gateway and 56.142.3.74 is the main external address for the gateway.

VPN connections enter via that address, (via DNS resolution of vpn.customer.com into 56.142.3.74)
Now I want to access a local server in that network externally. That server needs internal and external access.

Port forwarding for https seems to be the most obvious way to do it. I figured that out, but I can only connect via 56.142.3.74 (vpn.customer.com), but not via 56.142.3.75 (web.customer.com)

How can I set that up?

Am I missing something about a DMZ? (It seemed impractical to me, as the machine needs internal access for https, smb and ssh anyhow?)

The server runs Debian and has 2 physical interfaces (10G Ethernet)
The gateway has more than enough physical interfaces, but the COLT fiber connection obviously only one.

TIA

-e-