Skip to main content
NJAB
New Member
August 13, 2025
Question

Fortigate 100F Routing

  • August 13, 2025
  • 2 replies
  • 608 views

Hi,

 

I am new to Fortinet devices and routing in general and have a change to apply, we have a user that moved into the office locally recently from remote work needs to access an address, https://gis.********.co.nz/portal/home/index.html  and this leads to a local server onsite. There is an SSL cert applied for this server. I am assuming that there need to be a route to allow for the traffic going to that address to still work, where can I start looking at this or if someone can point me in the right direction it would be great.

 

Kind Regards,

2 replies

Toshi_Esumi
SuperUser
SuperUser
August 13, 2025

If the Web server is internal to your FGT, there must be a VIP policy for the public IP access from outside to translate/DNAT to the server's local IP at the FGT. Then you need to allow internal users (inside of the FGT) to the same outside public IP then "hairpin" back to get to the internal server by following the same VIP policy. 
You can follow this KB to set it up. If you're not familiar with CLI, you need to familialize yourself to it first.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-Hairpin-NAT-VIP/ta-p/195448

Toshi

ebilcari
Staff
Staff
August 13, 2025

If both the server and the host have their gateways on the FortiGate, routing configuration is not required. You should verify that the DNS server used by the host can resolve the server's private IP address. Additionally, a firewall policy must be created to allow traffic between the host subnet and the server.

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.