OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Virtual private networks »
  • Forward ports to web over site-to-site
« previous next »
  • Print
Pages: [1]

Author Topic: Forward ports to web over site-to-site  (Read 366 times)

blucobalt

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Forward ports to web over site-to-site
« on: January 09, 2023, 05:51:11 pm »
I am trying to set up my network so that I can access my network's local services from a public vps with a static IP.
Here is a diagram of what I'm trying to accomplish:
Code: [Select]
                                         
 x.x.x.x is the static ip of the vps
 z.z.z.z is the ip of whatever is running the local service i want accessible from outside
┌─────────────────────┐         ┌───────────┐           ┌────────────────────      ┌─────────────────┐
│local network        │         │local      │ internet  │ vps with static ip,      │                 │
│10.70.0.0/24         ├────────►│opnsense   ├───────────► runs latest       │ ─────► public internet │
│x.x.x.x:y->z.z.z.z:y │         │firewall   │ [wg or zt]│ opnsense          │      │ x.x.x.x:y       │
│                     │         │           │           │                   │      │                 │
└─────────────────────┘         └───────────┘           └───────────────────┘      └─────────────────┘
I was able to get the firewalls talking to each other over both wireguard and zerotier, but my portforwards don't work due to I think the way the (source?) nat is configured. How can I set this up? Thank you.
« Last Edit: January 11, 2023, 06:05:18 pm by blucobalt »
Logged

blucobalt

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: Forward ports to web over site-to-site
« Reply #1 on: January 11, 2023, 06:10:24 pm »
When I set up a portforward on the vps to point to an IP behind the local firewall, I can check the logs and see that the packets are reaching the destination. I confirmed this with UDP netcat. If I try going back the other way though, with TCP, it looks like the packets get lost between the destination and the local firewall. What should I do?
Logged

zan

  • Newbie
  • *
  • Posts: 44
  • Karma: 5
    • View Profile
Re: Forward ports to web over site-to-site
« Reply #2 on: January 25, 2023, 05:01:00 am »
Looks like you have an asymmetric routing, eg: return traffic from 10.70.0.0 network goes through your OPNsense default gateway instead of tunnel its originating from.
Try to set the 'reply-to' field of your pass rule on that tunnel interface to your tunnel gateway.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Virtual private networks »
  • Forward ports to web over site-to-site
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2