DMZ over VLAN to VM hosted on Internal network - problem
- April 10, 2019
- 7 replies
- 12851 views
Good Day experts,
So my idea is to have a webserver (hosted as VM via Windows HyperV) on my machine on the internal network, to be accessible via VLAN from DMZ interface on our Fortigate E61 FortiOS v6.0.4 build0231 (GA).
For the moment being, I know this sounds bad, but we're limited to the infrastructure currently available until we have this cloud hosted. We have the above mentioned fortigate unit and an ubiquity unifi managed switch between the internet and my local machine. My machine also has 2 NICs (one ethernet, the other Wifi)
I want to make said webserver accessible via the fortigate's DMZ port (on VLAN 20), which then goes to the same unifi switch as mentioned above (again, over VLAN 20) then to my local machine's ethernet NIC which is used exclusively by the VM for traffic.
These are the steps I have already taken:
[ol]Here are my results (as commands executed from the webserver at 192.168.2.10)
[ol]I still need to achieve the listed items above (specified as "BAD") (i.e. I need to hit the webserver from the internet, I neet the webserver to have internet access)
I hope I've explained with as much detail as possible. I've read up again and again but never quite see an article that addresses creating a VLAN on the DMZ port to a VM that's on the local internal network.
My knowledge and experience with networking is somewhat limited ( I mean I know ICMP atleast) and a few different things but I've been scouring the web with no luck as such on how to do this.
I have followed the cookbooks to setup a DMZ port but still run into the problem as mentioned above (I cannot set the policy's destination to a VIP, to allow wan traffic to my webserver). I have upgraded my firmware since but with no luck.
Please also see the screenshots of my actions attached.
