Accessing internal server by it's public VIP?
Hi guys,
I've done a search and come across a few answers but wonder if anything has changed in the later versions of FortiOS to make this simpler.
Suppose we have two servers on the internal-side of a Fortigate (in some cases on the same interface, in some cases on a different interface (VLAN)). They can communicate with each other using their own internal IP addresses, but how to we allow them communicate using their public/external IP addresses? We are using StaticNAT VIPs to assign these external addresses.
On some other firewalls you have a feature (sometimes called NAT Loopback) that allows servers like the ones above communicate using their assigned external addresses, I guess the routing engine of the fw recognises the external address as the Desintation on packets so runs them through the NAT processor. Is there any way of doing this on the Fortigate without using a Policy Route (which would not suit in our case due to the large number of external IPs going to various different VLANs)?
Thanks!
