answ(?): I think i found it (can you confirm? :-) ) : My firewall - port forward - rule was: destination"wan address", i changed that (for the mail server port rules) to "single host or network" and "public ipv4 for mailserver"
and question 2: can you confirm that this can also be arranged with ipv6? Like adding a virtual ipv6 to opnsense, and adding this to the port forward rule instead of wan address? pointing to the ipv6 of the nas?
answ(?): I think i found it (can you confirm? :-) ) : My firewall - port forward - rule was: destination"wan address", i changed that (for the mail server port rules) to "single host or network" and "public ipv4 for mailserver"You need to target the 1:1 public IP in the NAT rule. Your mail server won't care - it will send all traffic to the LAN IP of OPNsense.
Don't use NAT for IPv6. Give your mail server a static IPv6 and allow traffic to it. That will obviously only work if you have a fixed IPv6 delegation.
I think that is what I meant or I do not understand what you mean in regards to the port forward. I have the 1:1 public ip in the NAT rule. And in addition to this, the Firewall: NAT: Port Forward rule for port 25:interface: wandestination: public ip from range ( changed this from wan address to public ip from range)destination port range: SMTP (25)Redirect target IP: internal IPv4 of nas mailserverRedirect target port: SMTP
or why not to do it?
Firewall: Rules: WAN, + and change: