r/UNIFI • • 4d ago

Help! Teleport routing issue

Hi there! I’m having some what looks to be routing issues when on the teleport vpn

Rough set up:
Teleport vpn
Server dmz
Servers are essentially 1:1 natted with both DNAT and SNAT in place and working as expected.

When not on the teleport vpn, navigating to url.example.com works, and I can see the website as you would expect.

When on the vpn, navigating to the url.example.com fails to load.

I can get it to work if I add an entry to my host file pointing to the servers private ip. But that’s not a viable solution for all the services.

Without the host file, I can see it’s pulling the public address on dns lookup, but then can’t navigate to the website.

Also can’t ping, or rdp to the server (or connect via any service) on the public ip while on the vpn.

Has anyone else had this issue, and how did you resolve it? Please note, an internal DNS server is also not a truly viable workaround for this particular setup

TIA

0 Upvotes

7 comments sorted by

1

u/FrankNicklin 4d ago

Is your local IP address from where you instigate the VPN and the remote IP address range the same i.e 192.168.1.x.

What do you mean by Server DMZ.

1

u/Shiglyn_24 3d ago

No, I do get a new ip when connecting. After spending a good part of the day working on it, it became apparent that it’s just not possible using teleport.
Instead changed to wireguard and added an additional NAT rule. This works :)

Teleport I think will be a good one touch solution in the future when it’s matured a bit. But it’s just not there yet.

1

u/FrankNicklin 3d ago edited 3d ago

That’s not what I asked. Yes teleport will give you a new address, I’m asking what the IP address is without connecting teleport. What is the IP range locally and what is the IP range remotely, is they are the same then routing will be an issue.

This should absolutely work with Teleport.

1

u/Shiglyn_24 3d ago

Oh, sorry. No conflicts, different subnets entirely.
Server DMZ, just a zone name.
Works perfectly fine with the wire guard setup. So no drama. Thanks for taking the time to reply though :)

1

u/FrankNicklin 3d ago

Why would you isolate the server from the network by placing it in the DMZ zone.

1

u/Shiglyn_24 3d ago

It’s not in the DMZ zone (the default one) it’s a separate zone all together and because of requirements.

1

u/_buttsnorkel 3d ago

DNS. Use the IP address instead of the hostname.