This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

NAT Loopback (Hairpin NAT) to Access My Public Domains From Internal Zones (LAN) [Sophos UTM]

Hello Community,


I am out of solutions here and want your help,

I have Many web servers on the LAN, each has DNAT (Static IP)

I have many static IPs, all on one interface (PortB:0, PortB:1, PortB:2, ...) each subinterface has a static IP

I use Cloudflare to Manage DNS for my domains

  • when Cloudflare proxy switch is on(Hiding my real Static IP):
    • The domain sub.example.com to resolve to one of Cloudflare IPs and
    • I can access my domains (sub.example.com) from both Outside the network and from the webserver itself
  • when Cloudflare Proxy switch is off:
    • the domains will resolve to my Static IP (which is on PortB:0, PortB:1, ...)
    • I can access my domains from outside only because I have a DNAT rule But I Can't access them from inside the Server

I need to access my webservers regardless the status of the proxy in Cloudflare,

I tried several Rules I read about none of them worked,


I also contacted Sophos Support and they made a session but didn't solve it and said that they will revert back

I urgently need this to work


Appreciate your Kind Support





This thread was automatically locked due to age.