This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Internal Server from internal network with DNAT

Hi,

we have the following needs:

We want to be able to access an externally avilable service (api.example.com) from the internal servers whereas the external service is a NAT-SLB (Server Load balancing) and the the internal servers handling this services are on the same subnet, so we ran into the problem that the answer is not rerouted through the NAT. There is a solution: UTM: Accessing Internal or DMZ servers from Internal Networks using DNAT

The problem i see. When using the No. 1 DNS solution (which would work for us) we loose the ability to internally load balance that service.

Is there any way to also load balance this traffic internally???


This thread was automatically locked due to age.
Parents
  • I'm thinking that the problem is that the packet is already in the FORWARD chain and cannot be re-inserted into the INPUT chain.  What does Sophos Support say?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I'm thinking that the problem is that the packet is already in the FORWARD chain and cannot be re-inserted into the INPUT chain.  What does Sophos Support say?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children