# Can a host.v1 forward traffic to another server on the same lan?

**URL:** <https://openziti.discourse.group/t/can-a-host-v1-forward-traffic-to-another-server-on-the-same-lan/4644>\
**Category:** Support\
**Created:** [May 27, 2025, 11:14am UTC](https://openziti.discourse.group/t/can-a-host-v1-forward-traffic-to-another-server-on-the-same-lan/4644 "2025-05-27T11:14:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![TaoVonQi](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/taovonqi/32/3525_2.png) [@TaoVonQi](https://openziti.discourse.group/u/TaoVonQi)\
**Post date:** [May 27, 2025, 11:14am UTC](https://openziti.discourse.group/t/can-a-host-v1-forward-traffic-to-another-server-on-the-same-lan/4644/1 "2025-05-27T11:14:58Z")

</div>

Hi, I'm loving OpenZiti and in the process of setting up Zero trust for all my networking needs. I have a gitea instance running on Server A. The Controller and Router are running on Server B. Both Servers A & B are on the same LAN.

On Server A where gitea is running. I have a ziti-edge-tunnel systemd service with a bind policy. Then on my laptop (which is still in the same LAN) I have a windows tunneler running with a dial policy.

The service along with the necessary host & intercept configs are defined as well as the proper policies.

I was able to confirm this by running: `ziti edge policy-advisor services --quiet "giteaSvc"`

Here is the output:

OKAY : zen (1) -\> giteaSvc (1) Common Routers: (1/1) Dial: Y Bind: N

OKAY : qipione\_webSvcServer (1) -\> giteaSvc (1) Common Routers: (1/1) Dial: N Bind: Y

I have a feeling that the issue might be in here:

 ![intercept_config](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/6/642778285663e886467a2c892bae722815cb72c5.png)

```
                             Or here: 

```

 ![host_config](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/e/e31f0f2ba085273fa42194ab7370ccd1eb6ff393.png)

My question is: Can a host config forward traffic to another server on the same LAN without having another ziti-router on that server?

Also if the gitea server is not configured to handle any SSL certificates. It's just regular HTTP not HTTPS. Will that be a problem with how the intercept config is specified? ie [https://gitea.ziti/](https://gitea.ziti/)

It seems to intercept just fine: but I'm getting this error:

 ![gitea_error](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/0/0464c752f6ae37db81c6e24b85cc26b0b115db54.png)

Your help is greatly appreciated!!

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [May 27, 2025, 12:07pm UTC](https://openziti.discourse.group/t/can-a-host-v1-forward-traffic-to-another-server-on-the-same-lan/4644/2 "2025-05-27T12:07:40Z")

</div>

> [@TaoVonQi](#):
>
> Hi, I'm loving OpenZiti

Awesome!

> [@TaoVonQi](#):
>
> Can a host config forward traffic to another server on the same LAN without having another ziti-router on that server?

Absolutely. This is **exceptionally** common. This is referred to as ["zero trust network access"](https://openziti.io/docs/learn/core-concepts/zero-trust-models/ztna) as you end up "trusting" your network and traversing the underlay network. You do not need a router, nor a tunneler of any kind as long as the machine running a tunneler (a router/ziti-edge-tunnel/ziti desktop edge etc) can reach the target service via the underlay network.

> [@TaoVonQi](#):
>
> Also if the gitea server is not configured to handle any SSL certificates. It's just regular HTTP not HTTPS. Will that be a problem

I think this is your entire problem and confusion. Although OpenZiti is end to end encypted, and uses mTLS amongst all the OpenZiti overlay components, if your target service is HTTP (not HTTPS), your browser will need to use http as well.

So if you just use [http://gitea.ziti](http://gitea.ziti), I expect you'll be fine. Here's a couple of images to maybe help get you straight.

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/d/df30bd71454e4ddc976f8f30d177e8ad2bc06e82.png)

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/1/12e122219372e93f4b72e3dd17dba1ce80ee62b1.png)

---

<div class="post-metadata">

**Author:** ![TaoVonQi](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/taovonqi/32/3525_2.png) [@TaoVonQi](https://openziti.discourse.group/u/TaoVonQi)\
**Post date:** [May 27, 2025, 12:30pm UTC](https://openziti.discourse.group/t/can-a-host-v1-forward-traffic-to-another-server-on-the-same-lan/4644/3 "2025-05-27T12:30:59Z")

</div>

YES!!!! GOTTA LOVE THOSE IMAGES 🙂

OpenZiti FTW

---

<div class="post-metadata">

**Author:** ![snowman](https://avatars.discourse-cdn.com/v4/letter/s/f17d59/32.png) [@snowman](https://openziti.discourse.group/u/snowman)\
**Post date:** [June 2, 2025, 1:32am UTC](https://openziti.discourse.group/t/can-a-host-v1-forward-traffic-to-another-server-on-the-same-lan/4644/4 "2025-06-02T01:32:11Z")

</div>

> [@TaoVonQi](#):
>
> Can a host config forward traffic to another server on the same vlan

It doesn't even have to be on the same vlan 🙂  
any network resource that the host have access to in theory can be configured
