this post was submitted on 11 Apr 2024
5 points (85.7% liked)
OPNsense
508 readers
3 users here now
All discussions about the open source, FreeBSD-based firewall called OPNsense.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
This won't work. At the level you are looking to route the packets, there is no concept of which domain the request was intended for. You need a service that knows how to look at that packet, and forward it appropriately.
What you need to look into is a Reverse Proxy such as haproxy, caddy, or nginx (no specific order). I use haproxy to do something similar, but only on my internal network (with wireguard to access those when I am elsewhere).
Which ever reverse proxy you pick will be responsible for looking at those packets coming into it, and can determine the intended domain to route them appropriately, either through SNI, or more likely by unrwrapping the TLS on the packet.
I'd be careful with doing this, as you are letting whatever outside traffic into your network, so it's up to you to assess the risk for your use case and make the appropriate mitigations.
I'm familiar with reverse proxies, but that won't do ALL traffic, right? Just http or https?
Like if I want to ssh into the different servers, it won't handle that, will it? (Not saying ssh is my goal, I recognize how risky that would be)
It will accept all traffic sent to it via the ports it is listening on, just like any other service. It doesn't have to forward everything though, and what it does with that is up to it's configuration options and what you do with those.
Since you mentioned the wildcard cert, I assumed you were talking about services that speak
http/s
, and that they'd probably be on port443
. Those were a lot of assumptions by me.If it's not an
http/s
type service, what kind of services are we talking about?I'd like to self host matrix, and it seems like there are a bunch of not HTTP/s ports that need to be accessible
Can you maybe share some more information? Do you have a list of services, how you want them mapped, etc.?