Skip to main content
ICTServices
New Member
March 6, 2013
Question

Issue with Virtual IPs

  • March 6, 2013
  • 23 replies
  • 11078 views
I have a complex setup (with multiple levels of NAT), but put simply, my problem is this: When I create a Virtual IP for a server on the LAN (to allow incoming connections from a trusted partner network), that same Virtual IP seems to be used for all outgoing traffic from that server to the internet. My provider' s firewall only allows outbound traffic from our firewall, and so connectivity is blocked. Is it normal behaviour for a Virtual IP to be applied to outgoing traffic as well as incoming, or is there a setting I' ve missed that prevents this?

    23 replies

    ede_pfau
    SuperUser
    SuperUser
    March 8, 2013
    I don' t know of any feature you could use to mimick the MT router behavior. The FGT is a very versatile firewall but there are limits. What do you think about my suggestion (second paragraph in my last post)? Could you try that?
    goftari
    New Member
    March 8, 2013
    actually I didn' t get it. May you please be more specific? could you clarify me? Thanks
    ede_pfau
    SuperUser
    SuperUser
    March 8, 2013
    Em, yes, I was just brain-storming myself. Don' t think it would work. The key concept is that if traffic uses a VIP the return path is determined through the NAT table. The ingress web traffic doesn' t use any VIP on the FGT and accordingly there must be a default route pointing to the intranet interface. My idea was: can you think of a way to make web requests use a VIP, assuming at present they do not, they use the interface IP address.
    goftari
    New Member
    March 8, 2013
    You mean to find a way to source NAT the incoming traffic from the Intranet interface on the Fortigate?
    goftari
    New Member
    March 11, 2013
    Solved! Hi Ede, Assuming there' s no outgoing traffic to the Intranet interface except the reply traffic, I did solve my problem by changing the priority for the static default route to the Intranet gateway to 1000. This way the other two default static routes to the Internet having a priority of 0 will participate in ECMP load balancing and the route to the Intranet will just be used to show the next hop for the reply traffic coming in from the Intranet interface
    Thought Leadership. Security Summit. Thursday, November 12th, PGA National Resort, Palm Beach Gardens, FL.
    Thought Leadership. Security Summit. Thursday, October 8th. Disney's Grand Californian Hotel & SPA, Anaheim, CA.