Comment on OPNSense Reverse Proxies and Giving Internal Services Domain Names?
Imaginary_Stand4909@lemmy.blahaj.zone 7 hours agoSorry, I didn’t specify in my original post but I did plan to use .internal for my domains. And I never planned to open my ports on my firewall either so that’s good to know. But I’m still having issues despite this…
Here’s my Caddyfile:
# DO NOT EDIT THIS FILE -- OPNsense auto-generated file # caddy_user=root # Global Options { log { output net unixgram//var/run/caddy/log.sock { } format json { time_format rfc3339 } } servers { protocols h1 h2 } email [redacted] grace_period 10s skip_install_trust import /usr/local/etc/caddy/caddy.d/*.global } # Reverse Proxy Configuration immich.homelab.internal { handle { reverse_proxy 192.168.10.247:2283 { } } } import /usr/local/etc/caddy/caddy.d/*.conf
Here’s my firewall config (I allowed any source IP to Destination “This Firewall” & port 443/80 on my LAN/VLANs): Image
Here’s my Caddy configs:
And I did make a wildcard domain override (*.homelab.internal) in Unbound with this config:
Host = * Domain = homelab.internal Type = IPv4 IP = 192.168.10.247
I can ping my server’s IP, nslookup the homelab.internal domain, and ping homelab.internal. So the regular DNS entry is working, I just can’t get my reverse proxy to work…
frongt@lemmy.zip 4 hours ago
If it’s all internal (and you haven’t set up any extra firewall zones or rules) then you won’t need any firewall rules to allow it.
You should probably be able to just ping immich.homelab.internal right now, and make an http request and get something back too. Even if it’s an http error, that still means you’re talking to an http server successfully.
I haven’t used opnsense in years, and I’ve never used caddy, so I don’t know if the config is right, but it looks reasonable and the concepts are the same as what I’m used to.