Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Access from the Internet to the web server on the LAN side.
« previous
next »
Print
Pages: [
1
]
2
Author
Topic: Access from the Internet to the web server on the LAN side. (Read 2172 times)
greenhorn
Newbie
Posts: 8
Karma: 0
Access from the Internet to the web server on the LAN side.
«
on:
April 21, 2024, 09:32:15 pm »
Hello everyone.
It's possible that this topic has already been discussed, but I'm so confused that I can't find anything.
Namely, I have installed OPNsense, and on the interface (igc3) I have a server based on Apche2 connected, where I have a website in HTML.
The website runs on the local network, but how do I configure OPNsense so that I can view the website from the public network (I don't have a domain purchased at the moment). Currently, I would like to use the (permanent) public IP address assigned to me by the operator.
The (igc1) WAN interface has the address: 10.220.88.144
Interface (igc3) LAN I have the address: 192.168.100.22
I have configured: Firewall: NAT: Port Forward in such a way that from the internal WAN address: 10.220.88.144 - port (81) I can access the website at: 192.168.100.22
I enter 10.220.88.144:81 in the browser and a website opens on the Apache2 server.
What should I do to access this website from the Internet?
Please help.
«
Last Edit: April 21, 2024, 09:36:48 pm by suckling
»
Logged
Maurice
Hero Member
Posts: 1213
Karma: 158
Re: Access from the Internet to the web server on the LAN side.
«
Reply #1 on:
April 22, 2024, 01:38:04 am »
10.220.88.144 is not a public IPv4 address. Does your ISP use CGNAT? Or is there another router (with NAT) involved on your side?
Cheers
Maurice
Logged
OPNsense virtual machine images
OPNsense aarch64 firmware repository
Commercial support & engineering available. PM for details (en / de).
greenhorn
Newbie
Posts: 8
Karma: 0
Re: Access from the Internet to the web server on the LAN side.
«
Reply #2 on:
April 22, 2024, 06:36:45 am »
Hello Maurice
I have provided an example IP on the WAN port.
Does it matter what IP address I entered on the forum?
PS. Maurycy, I hope you weren't offended by my answer.
«
Last Edit: April 22, 2024, 07:19:35 am by greenhorn
»
Logged
greenhorn
Newbie
Posts: 8
Karma: 0
Re: Access from the Internet to the web server on the LAN side.
«
Reply #3 on:
April 22, 2024, 07:12:55 am »
Maurice, I'll give you the details.
I have access to the Internet via a wireless modem.
The public IP is 37.48.152.178
The IP on the WAN port is as specified above.
Firewall: NAT: Port Forward
Interface: HUAWEI
Proto: TCP
Source Address: *
Ports: *
Destination Address: HUAWEI address: 81
NAT IP: 192.168.100.22
Ports: 80(HTTP)
Logged
Maurice
Hero Member
Posts: 1213
Karma: 158
Re: Access from the Internet to the web server on the LAN side.
«
Reply #4 on:
April 22, 2024, 06:18:11 pm »
Using an RFC1918 as a placeholder for a public IP address was confusing, yes.
Your port forward rule looks fine. Does your ISP allow inbound connections? You could try a packet capture on the WAN interface to check for incoming packets to port 81.
Logged
OPNsense virtual machine images
OPNsense aarch64 firmware repository
Commercial support & engineering available. PM for details (en / de).
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Access from the Internet to the web server on the LAN side.
«
Reply #5 on:
April 22, 2024, 07:12:04 pm »
Also:
Filter rule association: Pass
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
greenhorn
Newbie
Posts: 8
Karma: 0
Re: Access from the Internet to the web server on the LAN side.
«
Reply #6 on:
April 22, 2024, 08:33:23 pm »
Maurycy - thank you for your answer.
I need to check if my ISP allows incoming connections.
Quote
You can try capturing packets on the WAN interface to see if the packets are coming to port 81.
Maurycy, can you describe in more detail where I can check if packets are coming to port 81.
Patrick M. Hausen, I have a question for you.
I'm not very familiar with OPNSENSE, can you elaborate on your answer?
Gentlemen, I have a common question for you: does Firewall: NAT: Outbound play any role in my problem?
Logged
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Access from the Internet to the web server on the LAN side.
«
Reply #7 on:
April 22, 2024, 09:01:58 pm »
The NAT Port Forward Rule you set up - down there is a field labelled "Filter rule association". Set that to "Pass", save and apply.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
greenhorn
Newbie
Posts: 8
Karma: 0
Re: Access from the Internet to the web server on the LAN side.
«
Reply #8 on:
April 22, 2024, 10:02:48 pm »
Patricki OK, I understood, thanks for the tip!
Regards
Peter
Logged
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Access from the Internet to the web server on the LAN side.
«
Reply #9 on:
April 22, 2024, 10:05:55 pm »
My name is Patrick and Maurice's name is Maurice. You are extraordinarily rude.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
greenhorn
Newbie
Posts: 8
Karma: 0
Re: Access from the Internet to the web server on the LAN side.
«
Reply #10 on:
April 23, 2024, 12:25:44 am »
Patrick M. Hausen
, I didn't think you were so sensitive about yourself.
Besides, the Germans are famous for this - Masters and subhumans -
you probably know this from History
?
Moreover, your year of birth does not impress me because I am 4 years older than you, Herr Baron von Hausen!
PS.
My typos were due to the fact that I used a translator.
Logged
greenhorn
Newbie
Posts: 8
Karma: 0
Re: Access from the Internet to the web server on the LAN side.
«
Reply #11 on:
April 23, 2024, 12:28:56 am »
Maurice (if I offended you), I'm sorry that I misspelled your name (NICK).
It wasn't intentional.
PS.
My typos were due to the fact that I used a translator.
Logged
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Access from the Internet to the web server on the LAN side.
«
Reply #12 on:
April 23, 2024, 08:54:08 am »
Insinuating I was a closet nazi sure makes it better. Consider this conversation ended.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
greenhorn
Newbie
Posts: 8
Karma: 0
Re: Access from the Internet to the web server on the LAN side.
«
Reply #13 on:
April 23, 2024, 10:59:35 am »
Jawohl Herr General - 88
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: Access from the Internet to the web server on the LAN side.
«
Reply #14 on:
April 23, 2024, 11:12:21 am »
Temp-banned greenhorn for posting (very far) off-topic.
Logged
Print
Pages: [
1
]
2
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Access from the Internet to the web server on the LAN side.