Skip to main content
Bth
New Member
June 21, 2016
Question

Fortinet Firewall Gateway Address

  • June 21, 2016
  • 3 replies
  • 4140 views

I have the Fortinet 60D firewall set up with NAT. My mail server, however, is seeing every user get reported as coming from the gateway IP address, instead of the IP address they are actually coming from.

 

Why? Is there some setting I might have wrong here? It seems the inbound IPs should be reported correctly.

 

Suggestions appreciated as this is causing serious issues with my mail server.

Brian

    3 replies

    rwpatterson
    New Member
    June 21, 2016

    The policy that points the traffic inward to your email server should have NAT turned off.

    Bth
    BthAuthor
    New Member
    June 22, 2016

    That worked for the inbound IPs, thanks.

     

    Now I notice that the servers that have a local IP, and are sending mail to another server that has a local IP, are showing the gateway IP address reported in the logs.  I would think they would report their own local IP address, not the IP of the gateway.  Or they would report their public IP.  Having the gateway IP reported is problematic.  

     

    Is there a similar tweak I can make for this?

     

    Thanks, Brian

    rwpatterson
    New Member
    June 22, 2016

    If you are accessing those other servers by public DNS name, then the traffic is exiting the FGT via the NAT policy and coming back in, hence the gateway address. The only way around it is to have your inside servers use a different DNS zone, pointing the public names to the private IP addresses.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!