Skip to main content
chiefexecutive
New Member
March 2, 2018
Question

NAT issue

  • March 2, 2018
  • 6 replies
  • 9997 views

hi,

I think this will be easy for some of you to tell me where the setting is to solve my problem:

i have to install an anonymous relay receive connector on our exchange for several external IPs - now the problem is, that on the exchange the originating IP where the connect seems to come from is the lan IP of our fortigate, not the external IP of the guy who tries to connect to our exchange... and so the relay doesnt work.. where can change the setting that the real originating IP comes to our server and not the one the fortigate has?

thank you & regards

    6 replies

    michael_lacey
    New Member
    March 2, 2018

    I'd look on the firewall policy that allows it access through the firewall, there is an option to turn NAT on or off

    chiefexecutive
    New Member
    March 2, 2018

    the policy rule in which the VIP for the portforwarding is has NAT turned OFF

    it doesnt matter if i turn it on or off, the issue is the same...

     

    i tried your tipp at a customer of mine ant there it works like you told, but not on our local forti..

    ede_pfau
    SuperUser
    SuperUser
    March 2, 2018

    1- reboot your FGT

    2- use

    diag deb ena

    diag deb flow filter port 25

    diag deb cons ena

    diag deb func ena

    diag deb flow trace start 20

     

    and post the results.

    gdifiore
    New Member
    April 5, 2018

    On your WAN to LAN policy that you created to allow the SMTP traffic inbound (the one with the VIP for your exchange server in it), do you have NAT enabled?  If so, you should turn it off.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!