Skip to main content
mspada
New Member
February 19, 2024
Solved

Fortigate - Vip on secondary network does not work

  • February 19, 2024
  • 5 replies
  • 2044 views

Hello,

Issue description:

Fortigate 60E (7.2.7) with 2 interface configured

1) WAN 151.22.102.209/29 public address (connected to Internet)

 

2) Port1 address 192.168.4.254/24

Secondary ip address 192.168.5.254/24

 

Internal Server1 192.168.4.200

Internal Server2 192.168.5.200

------------------------------------------------------------------------------------------------

Trying from the Internet:

Vip 151.22.102.210 to 192.168.4.200 WORKS!

by modifying the VIP in:

Vip 151.22.102.210 to 192.168.5.200 IT DOES NOT WORK

 

I can ping 192.168.5.200 from Fortigate

 

Thank You in advanced.

Regards

MS

Best answer by hbac

Hi @mspada.,

 

You are using the same public IP address for 2 internal servers. Do you have port forwarding enabled for each VIP to use different ports? If port forwarding is disabled, you should use different public IP addresses for each of them. 

 

Regards, 

5 replies

AEK
SuperUser
SuperUser
February 19, 2024

Hi

Do you confirm that the default gateway of internal server 2 is 192.168.5.254?

AEK
mspada
mspadaAuthor
New Member
February 19, 2024

Hi,

I don't know, I'm asking my client. 
I will let you know.
In any case, if in the policy from internet to internal lan I choose NAT (not with interface) but with an overloaded object created by me 192.168.5.254 it should still work, but unfortunately this doesn't happen
AEK
SuperUser
SuperUser
February 19, 2024

This should confirm that the default gateway of internal server 2 is not 192.168.5.254.

NAT as you did is a workaround but I think not the best & cleanest solution.

AEK
mle2802
Staff
Staff
February 19, 2024

Hi @mspada,

Can you try to run the debug flow when accessing the second VIP. Replace X.X.X.X with public IP where you accessing from.
diag debug reset

diag debug flow filter addr X.X.X.X
diag debug flow show ip en

diag debug flow show func en

diag debug console time ena

diag debug ena

diag debug flow trace start 999

Regards,

hbac
Staff
hbacAnswer
Staff
February 19, 2024

Hi @mspada.,

 

You are using the same public IP address for 2 internal servers. Do you have port forwarding enabled for each VIP to use different ports? If port forwarding is disabled, you should use different public IP addresses for each of them. 

 

Regards, 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!