Good morning everyone,
I am having significant difficulties configuring my IPFire following a change of internet provider. I kindly ask for your help.
I’ll try to briefly explain the situation. I’ll start with a description of the internal network and the fact that before the provider change, everything worked perfectly.
I have configured 3 zones: RED, GREEN (192.168.50.0/23), and ORANGE (192.168.60.0/24). In the ORANGE zone, I have a server with a file-sharing service listening on port 443.
Until a few days ago, the RED zone connected to the internet via PPPoE (with credentials), directly obtaining the static public IP address. In that situation, I had no problem reaching the file-sharing service both from outside (internet, via port forwarding) and from machines connected to the GREEN zone, using the public static IP.
After changing the internet provider (I switched to a fiber optic connection), I now have the provider’s router as the first device in the network. The WAN port of this device faces the internet and has the public static IP address (associated with a second-level domain I own, such as mydomain.it). One of the router’s LAN ports (192.168.1.0/24) is connected to the IPFire ethernet associated with the RED zone. The RED zone now has the static address 192.168.1.10 and gateway 192.168.1.1 (the LAN address of the provider’s router).
In this situation, I can no longer reach the server in the ORANGE zone from machines connected to the GREEN zone using the domain (and therefore the external static IP; everything works if I use the internal IP directly 192.168.60.239:443).
The problem is evidently the double NAT, which I have not been able to solve in any way.
I tried configuring IPFire as a DNS server for the GREEN zone and modifying the hosts file to map the file-sharing server address to the domain (192.168.60.239 mydomain.it) but it didn’t work (the domain continues to resolve to the external address, i do not know why).
I would like to create a firewall or routing rule to manage the situation but have not been able to.
I must clarify that I cannot configure the provider’s router in bridge mode, so I have to deal with the double NAT.
Does anyone have any suggestions?
Thank you in advance!