Public Domain Application Inaccessible from Local Network
  

Samianto Lv1Posted Oct-17-2025 11:29


Our infrastructure includes applications hosted under both local domain and public domain configurations. A recurring issue was observed where applications accessed via the public domain were inaccessible from within the local network, particularly when traffic was routed through the Sangfor NGFW (Next-Generation Firewall).

Root Cause
This behavior is typically caused by the firewall's handling of internal requests to public IP addresses that resolve back to internal servers. Without proper configuration, the firewall may block or misroute these requests, preventing successful access.

Solution: Hairpin NAT Configuration
After investigation and testing, the issue was resolved by enabling and configuring the Hairpin NAT feature on the Sangfor NGFW. Hairpin NAT allows internal clients to access internal servers using their public IP addresses by redirecting the traffic appropriately within the firewall.

Benefits

Seamless access to public domain applications from internal networks.
Improved compatibility with services that rely on public DNS resolution.
No need to maintain separate URLs or DNS records for internal and external access.

Recommendation
For environments using Sangfor NGFW and hosting services accessible via the public domain, it is recommended to
enable Hairpin NAT.
Ensure proper NAT rules are configured to map public IPs to internal servers.
Test access from multiple internal segments to confirm functionality.

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x

Like this topic? Like it or reward the author.

Creating a topic earns you 5 coins. A featured or excellent topic earns you more coins. What is Coin?

Enter your mobile phone number and company name for better service. Go

Medic Lv2Posted Dec-05-2025 12:10
  
In my configuration, it only works if Translate Src IP To is set to IP Address or Network Object.
It does not work when Outbound Interface is selected.

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
admin Posted Nov-11-2025 08:59
  
Thanks for sharing. Your article has been adopted by Sangfor Community and rewarded with 4000 coins.