Skip to main content
comas17
New Member
January 25, 2017
Question

Double ISP / WAN connection policies

  • January 25, 2017
  • 1 reply
  • 3200 views

Hi all Device: Fortigate 60D Firmware 5.2.1 build 618 Until one month ago we were using only one WAN, connected to one ISP. We were using some public ip addresses and with the appropriate policy it was possible to connect to some websites hosted internally using the public dns name (example: we have "priv.ourcompany.com", public IP is 33.44.55.66 and also from internal network we were able to connect to this site using the url [link]http://priv.ourcompany.com)[/link] We are now also WAN2, connected to another ISP (and another public IP) and  with static routes and policy router we have configured that normally all traffic from internal to wan uses WAN2 (WAN2 is fiber connection, WAN1 is a simple ADSL) But now it is impossible, when we are in the internal LAN, to connect to our internal website using public name and/or ip. All is working correctly if I'm connecting from external. How can I do this path ? internal lan --> wan 2 --> internet --> wan 1 --> internal lan (my web site?)

 

Thank you

    1 reply

    Carl_Wallmark
    New Member
    January 25, 2017

    Hi,

     

    I think you should use Hairpin NAT, "match-vip"

    http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD36202&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=21760958&stateId=1%200%2021762142

     

    However, as you describe it, both the client and server is on the same internal LAN, so you might need to do a policy

    LAN -> LAN with "match-vip" enabled (CLI only)

    But I´m not sure, as it is a strange setup ;)

     

    Another alternative is to have two DNS servers, one that is public, and one that is internal, on the internal DNS record you just set the internal IP of the server.

    External www.mycompany.com -> 195.134.10.10 (for example)

    Internal www.mycompany.com -> 192.168.1.10 (for example)

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.