OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 23.1 Legacy Series »
  • Forward the same port to two different systems
« previous next »
  • Print
Pages: [1]

Author Topic: Forward the same port to two different systems  (Read 1139 times)

amd.64

  • Newbie
  • *
  • Posts: 21
  • Karma: 0
    • View Profile
Forward the same port to two different systems
« on: July 17, 2023, 06:36:05 pm »
I posted this in 22.7 Legacy Series but didn't get much traction. I have upgraded to 23.1.11 in part hoping that an update would get it to work, but it is still not working.

I have an Exchange server and now a webserver on the same network, both use 443 for HTTPS.

I have a block of five static IPs from my ISP. Is it possible to have the Exchange server coming in on 443 on one public IP and the webserver coming in on 443 on another public IP?

I have created a virtual IP for each of the IPs I want to use.  I have created the port forward rules in the image below but all traffic from both IPs is forwarded to the exchange server.

Can anybody provide insight or provide a link on how to do this?

Logged

sorano

  • Full Member
  • ***
  • Posts: 153
  • Karma: 21
    • View Profile
Re: Forward the same port to two different systems
« Reply #1 on: July 17, 2023, 06:38:14 pm »
1:1 NAT for each server should solve this easily.
Logged
2x 23.7 VMs & CARP, 4x 2.1GHz, 8GB
Cisco L3 switch, ESXi, VDS, vmxnet3
DoT, Chrony, HAProxy + NAXSI, Suricata
VPN: IPSec, OpenVPN, Wireguard
MultiWAN: Fiber 500/500Mbit dual stack + 4G failover

--
Available for private support.
Did my answer help you? Feel free to click [applaud] to the left

amd.64

  • Newbie
  • *
  • Posts: 21
  • Karma: 0
    • View Profile
Re: Forward the same port to two different systems
« Reply #2 on: July 17, 2023, 06:51:24 pm »
I have created NAT rules for both, but all traffic still goes to the exchange server.

I attempted to add an image of the two NAT rules, not sure why it was not added
« Last Edit: July 17, 2023, 06:57:34 pm by amd.64 »
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6935
  • Karma: 584
    • View Profile
Re: Forward the same port to two different systems
« Reply #3 on: July 17, 2023, 07:03:17 pm »
The destination address needs to be a single host, i.e. 50.78.239.106 or 50.78.239.106/32 - if you specify /29 for the destination, that means all 8 addresses in that prefix are matched by the first rule.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

amd.64

  • Newbie
  • *
  • Posts: 21
  • Karma: 0
    • View Profile
Re: Forward the same port to two different systems
« Reply #4 on: July 17, 2023, 08:14:30 pm »
Quote from: Patrick M. Hausen on July 17, 2023, 07:03:17 pm
The destination address needs to be a single host, i.e. 50.78.239.106 or 50.78.239.106/32 - if you specify /29 for the destination, that means all 8 addresses in that prefix are matched by the first rule.

Awesome!

Thank you. I have only tested it once, but it did work. I had an tab open to Exchange and one to the web site.

Thank You much

I tried Googling this but everything I found was the more simple port forwards.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 23.1 Legacy Series »
  • Forward the same port to two different systems
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2