Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
24.7 Production Series
»
port forward on ip alias not working
« previous
next »
Print
Pages: [
1
]
Author
Topic: port forward on ip alias not working (Read 817 times)
Madifor
Newbie
Posts: 35
Karma: 0
port forward on ip alias not working
«
on:
July 21, 2024, 11:43:41 am »
I have an the following issue
On an 'external' interface i have configured a fixed ip and an alias/ virtual (alias)ip address.
As shown in the attachment , i configured port forwards on the interface ip and port forwards for the virtual ip.
When trying webpage using the interface ip , forwards works perfectly and i reach the 1st internal system.
When trying webpage using the virtual ip , i am reach the gui of the firewall and not the 2nd internal system.
Logged
doktornotor
Hero Member
Posts: 709
Karma: 70
Re: port forward on ip alias not working
«
Reply #1 on:
July 21, 2024, 11:48:53 am »
Trying how? 10/8 is RFC1918 space, not accessible from outside. From inside, you are into the NAT reflection can of worms plus it is very much pointless since you can access those directly without involving your firewall/router at all.
Not really sure what are you trying to do there, to use multiple webservers behind a single IP, I would suggest a reverse proxy, such as HAproxy or nginx.
«
Last Edit: July 21, 2024, 11:50:25 am by doktornotor
»
Logged
Madifor
Newbie
Posts: 35
Karma: 0
Re: port forward on ip alias not working
«
Reply #2 on:
July 21, 2024, 01:40:50 pm »
The so called csc lan is a special internal lan whclich can only be acccessed when at the corporate lan only and the destination network is a testing/ development network also internal only., but not to be exposed / directly accessible via routing from the corporate lab.
The goal for the forward is to be to access the ftp/tftp server from address x and the installed terminal server from server y. I know the picture only shows htttp(s) but that is for easier to test as the is storage also has a web portal running
Logged
doktornotor
Hero Member
Posts: 709
Karma: 70
Re: port forward on ip alias not working
«
Reply #3 on:
July 21, 2024, 02:06:48 pm »
Quote
The goal for the forward is to be to access the ftp/tftp server
Uhm. Testing with HTTP(S) will not help you at all, even when you get it working, it will not keep working when you switch the rule to FTP simply due to how FTP protocol and active/passive modes work.
For FTP, try the FTP proxy plugin, perhaps. TFTP does not handle NAT any better, used some kernel helper module on Linux and was another royal PITA.
Logged
Madifor
Newbie
Posts: 35
Karma: 0
Re: port forward on ip alias not working
«
Reply #4 on:
July 22, 2024, 06:40:59 am »
Agree on that,based on different requirements of the ftp protocol.
FTP/ tftp will mainly being used on the development network to upload/ download the correct software, configurations / reports from/to the devices.
Having multiple http(s) servers with different tasks to be reached on that isolated networks is the 1 st challenge.
So far I am not able to reach the web server which I want to reach using one of the ip aliases.
When I http(s) to the virtual / ip alias I only get to the gui of the firewall it’s not correctly forwarded.
Logged
Madifor
Newbie
Posts: 35
Karma: 0
Re: port forward on ip alias not working
«
Reply #5 on:
July 22, 2024, 07:03:06 am »
Sorry Guys , I am in the wrong forum… .
Al my issues are related to the 24.1.x version and not 24.7 sorry for that. Not sure if a moderator can move it to the correct one ?
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
24.7 Production Series
»
port forward on ip alias not working