Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» Firewalling» How To Route Port-Forwarded Response Back To Original Non-Default Router
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: How To Route Port-Forwarded Response Back To Original Non-Default Router  (Read 1259 times)
0 Members and 1 Guest are viewing this topic.
292957
Newbie
*
Offline Offline

Posts: 9


View Profile
« on: February 21, 2011, 10:52:59 pm »

I'm a newbie to pfSense 2.0.  I need someone enlight me how I could handle this situation.

I have two separate pfSense router A & B resided on the same LAN.  I have a server running mail and FTP with default gateway set to A.  The server also run a webserver that need to be port-forward from B.  With the default gateway set to A how I'm able to route the webserver result back to B? Huh
Logged
jimp
Administrator
Hero Member
*****
Offline Offline

Posts: 13068



View Profile
« Reply #1 on: February 22, 2011, 11:07:15 am »

You would have to do policy routing on the server itself to properly handle that, it can't be done in the firewall.

Why do you need two separate routers? Why not do everything in one firewall? The issue wouldn't exist then...
Logged

Need help fast? Commercial Support!

Co-Author of pfSense: The Definitive Guide. - Check the Doc Wiki for FAQs.

Do not PM for help!

Donate to the project | My Wish List
292957
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #2 on: February 22, 2011, 11:39:19 am »

Well actually both pfsense routers are already dual-WAN (altogether 4 WAN).  The two pfSense are used to serve 10+ servers each.  Just only that particular webserver has such a requirement because the public address cannot be changed.  That server is a WS08R2 and I'm not too sure how it can be configured to perform this kind of source routing (based on source port).

I remember when I browse the forum I came across several similar cases that I do not fully understand how they were done.  One case mention using ARP to twist the mac address.  Another case was some kind of double NAT??  And one case reagrding setup of firewall routing rule and manipulate of outbound NAT.

Am I misunderstand those cases?  Is there really no way to configure what I want?

Anyway thanks for your assistance!
Logged
jimp
Administrator
Hero Member
*****
Offline Offline

Posts: 13068



View Profile
« Reply #3 on: February 22, 2011, 11:57:07 am »

The problem is not in the firewall, either one of them. It's that your web server doesn't know how to properly send the traffic back where it came from. It may not have any way to distinguish that.

I'm not sure Windows has any method to pull that off properly.
Logged

Need help fast? Commercial Support!

Co-Author of pfSense: The Definitive Guide. - Check the Doc Wiki for FAQs.

Do not PM for help!

Donate to the project | My Wish List
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.026 seconds with 20 queries.