Re: [pfSense] [Bulk] Re: DNS-based inbound NAT?

2014-12-14 Thread Mike Bobkiewicz
Hi Piba, thanks for the hint, haproxy does the trick! Best regards, Mike Am 14.12.2014 um 21:41 schrieb PiBa : > HAProxy can also be used for this. > > Brian Henson schreef op 14-12-2014 20:13: >> I second using a reverse proxy for this. You can use the squid package or >> even use the Mod_se

Re: [pfSense] [Bulk] Re: DNS-based inbound NAT?

2014-12-14 Thread PiBa
HAProxy can also be used for this. Brian Henson schreef op 14-12-2014 20:13: I second using a reverse proxy for this. You can use the squid package or even use the Mod_security and proxy pass directive On Sun, Dec 14, 2014 at 1:44 PM, Yehuda Katz > wrote: HTTP H

Re: [pfSense] DNS-based inbound NAT?

2014-12-14 Thread Brian Henson
I second using a reverse proxy for this. You can use the squid package or even use the Mod_security and proxy pass directive On Sun, Dec 14, 2014 at 1:44 PM, Yehuda Katz wrote: > > HTTP Host headers are not even seen by the firewall unless some type of > Deep Packet Inspection is running or the f

Re: [pfSense] DNS-based inbound NAT?

2014-12-14 Thread Yehuda Katz
HTTP Host headers are not even seen by the firewall unless some type of Deep Packet Inspection is running or the firewall is the destination and runs a proxy to the other servers. The alias method suggested will not work in this case (as you found) because pfSense does not check the host headers.

[pfSense] DNS-based inbound NAT?

2014-12-14 Thread Mike Bobkiewicz
Hello, we have a problem: we´re running a pfSense 2.1.5 firewall with a single WAN address in front of a DMZ zone with two web servers. What we now want to do is that pfSense redirects a http call to server1.example.com to webserver 1 and a http call to server2.example.com to webserver 2. We hav

Re: [pfSense] More ports

2014-12-14 Thread Ryan Coleman
> On Dec 13, 2014, at 8:06 PM, Chris Bagnall wrote: > > (I've listed HP models because that's what I've experience with, no doubt > other manufacturers have similar models. Just watch out for some of the cheap > Netgears that claim to be 'managed' (model beginning J I think) - they have a > h