External IP for VIP changes but no routing
Hi,
We are replacing a FG-80E with an FG-81F (7.2.8) and hit the following issue when changing the external IP address for our VIPs from test to live that the live DMZ machines are not contactable from the internet.
We have setup the FG-81F with a temp external IP address A.A.A.100 and two VIPS A.A.A.101 and A.A.A.102, these are both mapped to 10.10.10.13 and 10.10.10.14 and a test Linux machine is sitting there and is quite happy, it can be contacted from the outside and ping to the outside world. So it seems that the firewall policies are happy.
When we replace the IP addresses with the actual live ones A.A.A.50, and VIPS with A.A.A.51 and A.A.A.52 then our live Linux servers (10.10.10.13 and 10.10.10.14) can not be contacted externally and they can not ping out. They can be contacted from the LAN->DMZ though, if the machines on the LAN contact them via their external IP addressed they can, however external machines can not contact them.
The only changes we make from test to live is to change the FG-81F IP address and the 2 vip addresses (and to unplug the old GF-80 from the fiber). If we put the old FG-80E back in then the live Linux machines are available again. If we change the FG-81F's ip and vips back to the test ones and put the test LInux machine behind it then it works perfectly again.
We are thinking this is some kind of ARP issue as we have a 2nd FG-81F with essentially the same setup and it works fine, we have matched the firewall policies between the two machines and they all match.
Is this a thing that if you change the vip's then you have to do something with the arp as well?
Thanks in advance
