Skip to main content
AbdoSoft
New Member
November 11, 2020
Question

Allow traffic between two interfaces problem

  • November 11, 2020
  • 1 reply
  • 5670 views

Hi Everybody,

I have a problem with allowing traffic between two interfaces of FortiGate 101F. I need to separate a server on an interface different of the LAN I chose DMZ Port , I moved the server to the DMZ and do the configuration the Server Can ping my PC on LAN and I can ping the server on the DMZ but I can't Use any service on this server ( File Share , Remote Desktop , …) only ping is running when I open the logs I found " TCP Reset from client - TCP reset from server " , But when I replaced the Server with a TP-Link Router with the same IP I can access it through the web , Can anyone help me solve this problem, here is the configuration and the logs are attached.

 

 

    1 reply

    lobstercreed
    New Member
    November 12, 2020

    Is there a firewall on the server itself?  That's what it sounds like to me.

     

    It won't solve your problem (PLEASE don't leave it like this), but it should point you in that direction if you turn on NAT for the LAN -> DMZ rule.  It might begin working because the server will think the client is in the same subnet and presumably the server firewall was set up to allow intra-subnet traffic (not always, but I've seen it before).

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.