Question
Internal PC' s can' t see Internal web server with static external IP- misconfig routes- (outside can)
Sorry for the lame title, but I am at wits end, I am going cross eyed here. Plus I can' t just change items since the router is located in a colo about 100 miles away. Here is what I have... Internal Server that is hosting a website, server has a static external IP. Everyone out of the networks behind the FortiGate can see it (from home, office, etc). All internal networks can not access the site. The following IP' s listed are changed for privacy, but here is my info from the colo site, and the way it is setup now- I am pretty sure the issue is with my routing, but I' m afraid to change anything for fear everything becomes inaccessible... From CoLo Setup Sheet: WAN Side of Firewall IP: 60.182.173.217 (unusable) Subnet: 255.255.255.128 Default Gateway: 60.182.173.130 LAN Side of Firewall: 62.217.41.48 (unusable) Subnet: 255.255.255.248 First IP: 62.217.41.49 (assign to your Router/Inside Interface) Available range: 62.217.41.50-54 Broadcast: 62.217.41.55 My ForitGate as configured: Network: Switch- 62.217.41.49/255.255.255.248 Switch Secondary- 10.1.1.1/255.255.222.0 WAN1- 60.182.173.217/255.255.255.128 Router: IP: 10.10.2.0/255.255.255.0 Gateway: 62.217.41.49 Device: Switch IP: 10.1.1.0/255.255.255.0 Gateway: 62.217.41.49 Device: Switch IP: 62.217.41.48/255.255.255.248 Gateway: 62.217.41.49 Device: Switch IP: 0.0.0.0/0.0.0.0 Gateway: 60.182.173.130 Device: wan1 IP: 60.182.173.128/255.255.255.128 Gateway: 60.182.173.130 Device: wan1 On the last route, the IP automatically changes to end with 128 with that subnet. I know I have something very wrong here, but I am just too afraid to touch it when I am not right next to the system, and everything has been working pretty well, but we have an internal system- 10.10.2.10 that needs to access the web server that is sitting on 62.217.41.51, a web server that is available to everyone on the outside. Please advise with any input- feel free to call me an idiot :)
