Skip to main content
Contributor III
July 11, 2008
Question

Intranet (SOLVED)

  • July 11, 2008
  • 16 replies
  • 7367 views
Hello, I need to know what type of policy or how do I go about setting up an Intranet for my office. I have my webservers on Subnet 1 and my Office is connected to Subnet 2. I would like for my office to be able to access a 2 websites that' s on one of my webservers via an Intranet before if the internet goes down they are still able to access these websites via the intranet etc. How do I accomplish this? The servers and the office is behind a FortiGate 60B firewall in Interface Mode. I have the latest firmware available on this unit.

    16 replies

    UkWizard
    New Member
    July 11, 2008
    I don' t quite follow you, could you elaborate
    Contributor III
    July 14, 2008
    ok basically what I want to do is have my employees access the a website on one of my servers via the ipaddress without going through the internet. In other words lets say my internet goes down in my office, I would like my employees to still be able to access a website in my office through the LAN or network.
    UkWizard
    New Member
    July 14, 2008
    Where is the intranet server? in the local lan or DMZ? This is more a DNS question, and sounds like its not really related to the firewall. Usually, for an intranet site, it should resolve to its own internal IP. thus not going through the firewall. Unless you have your users using a ISP DNS server instead of a local one, or your intranet has a VIP on it to an external IP, (which would make it an extranet) Sorry, need more info still, as question doesnt make sense as it is.
    Contributor III
    July 14, 2008
    I do not have an internal DNS server. The webserver is located on the DMZ. I have a VIP ponting to the server' s internal IP Address which is something like 10.10.10.10. My employees desktop computer are connected to Subnet 1. Basically I have 1 webserver connected to the DMZ port of the firewall and my employees desktop computer is connected to the Internal networks (port 1) on my firewall therefore the webserver and the internal networks is in the same office on 2 different subnets. I would like to have my internal users to be able to access the website on my webserver via the intranet therefore eliminating the need to access the website through the internet.
    UkWizard
    New Member
    July 15, 2008
    So do you have an external IP setup for the Intranet VIP? If so, then when the internet goes down it will still continue to work, but its probably the DNS thats stopping it working. I presume all your clients use an ISP DNS server(s), and you have a vip to resolve your ' intranet.yourdomain.com' . Yes? In which case its failing because of the fact you are using your ISPs DNS There is a couple of ways to resolve this; 1. Setup an Internal DNS server and use that for clients DNS settings. or 2. add a manual entry on the ' hosts' file of every desktop pc, pointing to the VIP OR the real IP. The latter is the easiest if you do not have many machines to configure. In reality, unless you need external access for the intranet server, then you wouldnt need a vip anyway. Just routing to the DMZ subnet would work....
    Contributor III
    July 15, 2008
    I tried modifying the hosts file but still no luck. Any ideas why that is not working? Again The Webserver that' s hosted the site is the DMZ (192.168.70.2) and the employees desktop computers is on the internal (192.168.50.1)
    UkWizard
    New Member
    July 21, 2008
    You shouldnt need to use VIP' s, why do you need to do that? How is it currently setup? are you saying you then have two websites, one external and one intranet, on the one server. If so, are you using two different listening ports? as the alternative is using different IP addresses on the server itself. So say the external one listens on the real server IP. And then use another IP for the intranet to listen on. Internal DNS should resolve to the relevant IP its listening on, you shouldnt have to use VIPs for internal access. But obviously it can be done. Multiple external VIP' s would work as well.
    rwpatterson
    New Member
    July 21, 2008
    The server should already have a virtual mapping to the address at 192.168.70.2. The outside world will see your server via the Virtual IP mapping. At the same time, your inside clients will see the real IP addresses. Both will work simultaneously. After reading the above post, is the outside server and inside server the same physical box?
    Contributor III
    July 21, 2008
    After reading the above post, is the outside server and inside server the same physical box?
    Yes it is. Again I have only 1 webser and it is hosting multiple websites ok. One of the 3 websites are public and the other 2 I would like to have accessible only to our LAN (Intranet). I have a VIP mapped to the Public website only but not to the 2 website that I would like to have on the Intranet only. I do not have a DNS server on my LAN therefore I can' t do this with DNS. I was hoping to either do it my adding an entry in the hosts file of each computer or by just having the users on the LAN type in the local IP address of the website (192.168.2.71) for each of the intranet websites. My Fortigate 60B is in Interface Mode and the Webserver (websites) is connected to the DMZ and my LAn is connected to Interface 1 on the same Fortigate firewall. How so I setup 2 websites to be accissible only via the LAN?
    UkWizard
    New Member
    July 21, 2008
    Yes thats correct, you literally just need policies to allow the traffic, either to the individual Ip addresses, or just to the entire subnet. Ie. you could just alllow all internal to all DMZ. Then use the IP addresses in the URL of the browser. A nicer way, is to add a couple of url redirects on the external facing website. For example, if your external website url is www.mysite.com, create a couple of redirectors on the website like; www.mysite.com/intranet & www.mysite.com/portal and have them redirect to the ip addresses (ie http://192.168.2.71 and http://192.168.2.71 ) Then your users do not have to remember the ip addreses and you can change them to redirect somewhere else later if needed. Hope thats make sense, in summary create a folder called intranet and portal under the root of the public facing website, with the default web file doing the url redirect. Really though, you should have intranet servers on seperate servers and preferably on the internel network. Else, if the external facing website got hacked, they would have access to your intranet websites as well.
    Contributor III
    July 22, 2008
    Thank you UKWizard for all of your help. The solution you provided below worked fine: I' ll give this a try. This is from one of your post: f you use the host file approach, set up a policy: Interface1 -> DMZ, client IP (192.168.50.x) -> 192.168.70.2 Don' t use the VIP address, no NAT. I do understand the redirect method you speak of but I was able to get it to work by modifying the host file therefore they will be able to get to the website by typing in the name. I also agree that I should have the intranet websites on a seperate server incase the public website gets hacked somehow but I have limited server' s to work with. Thanks again
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!