News: This forum is now permanently frozen.
Pages: [1]
Topic: Re: NAT Redirection Workarounds  (Read 2757 times)
« on: July 20, 2011, 02:28:04 »
Jarhead *
Posts: 18

Any chance for NAT redirection in the new version?? I have to be able to access LAN resources using my WAN domain name. I'm about to switch to pfsense just for that feature but I'd rather not. Unless there's another way you know of??
« Reply #1 on: July 20, 2011, 15:43:06 »
Fred Grayson *****
Posts: 994

Several workarounds are available that can work for you.

You can add hosts to the m0n0wall DNS forwarder, but then you must use m0n0wall's IP for client DNS resolution and you have to have resolvers or other forwarders specified within m0n0wall.

You can add entries in your machines hosts file, and verify that hosts is consulted before DNS by your client machines. For a few entries in a few machines this is tolerable. But if you have frequently changing hostname/IP combinations and/or numerous machines coming and going this can be a lot of work to keep current.

--
Google is your friend and Bob's your uncle.
« Reply #2 on: July 20, 2011, 16:51:30 »
Jarhead *
Posts: 18

I cant use the hosts file. I need to connect to devices that don't have a hosts file, ie alarm system, dvr, home automation system, ip cameras.

How can I forward my whole LAN??
Does that mean there will never be the NAT redirection feature added??
If it's a security concern, Why not give us the option to use it?
« Last Edit: July 20, 2011, 16:53:22 by Jarhead »
« Reply #3 on: July 20, 2011, 17:04:36 »
Fred Grayson *****
Posts: 994

The hosts file you need to make entries in is on the machine you are connecting from, not the device you are connecting to.

I can't speak to what will or will not be in future versions of m0n0wall. I'm not a developer and don't speak for the developers.

The reason there is no NAT redirection in current versions of m0n0wall is that the capability does not exist in the underlying FreeBSD version.


--
Google is your friend and Bob's your uncle.
« Reply #4 on: July 20, 2011, 19:46:03 »
Jarhead *
Posts: 18

Let's just say the hosts file is not an option and leave it at that.

Is there a way to forward my whole lan with the dns forwarder?
« Reply #5 on: July 20, 2011, 20:34:22 »
Fred Grayson *****
Posts: 994

In the System General Setup Page, provide one or more DNS servers.

Enable the DNS Forwarder and add the appropriate host record into the forwarder (Host, Domain, IP and optional Description).

Configure every machine in your LAN to use the forwarder for DNS resolution.
« Last Edit: July 21, 2011, 00:32:25 by fredg »

--
Google is your friend and Bob's your uncle.
« Reply #6 on: July 20, 2011, 22:36:15 »
Jarhead *
Posts: 18

Enable the DNS Forwarder and add the appropriate host record into the forwarder (Host, Domain, IP and optional Descrirption).

What Host? You mean one entry for every host on my lan?
« Reply #7 on: July 20, 2011, 23:34:27 »
Fred Grayson *****
Posts: 994

The WAN host in your domain that you are trying to reach from your LAN.

If this does not answer your question, then this portion of the thread will have to be moved to an appropriate forum as it is not 1.8 Development related.

--
Google is your friend and Bob's your uncle.
« Reply #8 on: July 21, 2011, 14:24:56 »
Jarhead *
Posts: 18

The WAN host in your domain that you are trying to reach from your LAN.

If this does not answer your question, then this portion of the thread will have to be moved to an appropriate forum as it is not 1.8 Development related.

No need to move it unless you want to. I'm done trying and I will use pfSense instead for now and wait to see if the new m0n0wall adds this option.
I'm just curious if you have ever done this?? Because it won't work. I need to be able to access these devices by ports not by hostnames.
« Reply #9 on: July 21, 2011, 14:29:35 »
Fred Grayson *****
Posts: 994

It works for me.

What IP do you get when you ping the fully qualified host name from the LAN with and without the DNS forwarder enabled?

Exactly what information are you putting into the forwarder?

Are you using the m0n0wall LAN IP for your LAN client's DNS?
« Last Edit: July 21, 2011, 14:33:38 by fredg »

--
Google is your friend and Bob's your uncle.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines