Hello,
Right now I have a RB3011 router and a CRS326 switch at home. Since I don't want to open up ports from the internet into my LAN I'm going to configure a DMZ and put my server here where it will be "isolated" from the rest of the LAN.
Right now if I try to access my external IP from my LAN I will get directed to my router. I can "fix" this by configuring Hairpin NAT.
That way I can point www.example.com to my external IP and get to the correct site. Without Hairpin NAT I will get to my routers webUI.
My question is if I can add a second network cable from my ISPs modem (yes I can get more than 1 IP) and make my DMZ use this IP and my LAN use the first one and have the LAN-traffic access the DMZ external IP without using Hairpin NAT?
I hope you understand what I mean.
Since the LAN won't be able to access the internal IP of the DMZ I can't configure an internal DNS server to point to the internal DMZ IP.
I just want to be able to access www.example.com on it's external IP from inside my LAN.
Is this possible or is Hairpin NAT the only way? I've read somewhere that you should avoid hairpin nat on production. Why is that? Is it adding unnecessary overhead on the router or something?