Question
Not successful with Virtual IP
I am having a problem creating a publicly accessible server using a new Fortigate 200B. I am new to Fortinet equipment but have been successfully using Cisco gear for a number of years and am frustrated being a new user again. I hope you might be able to point out what stupid thing I am doing wrong. Short story: I create a Virtual IP and corresponding Firewall Policy for a server on the DMZ. Clients on the LAN can see the server. Clients on the Internet cannot. Bypassing the Fortigate and putting the server directly on the cable modem works fine. From the documentation and tech notes this seems like it should be an easy thing to do. What am I missing? Long story: I have done a factory reset on the Fortigate and tried to create the bare minimum configuration to aid in troubleshooting. I am running “v4.0,build6539,110520 (MR2)†which is the special build of MR2 patch 7 that supports FortiAP’s. I am running in Interface mode (not Switch mode). (This also means I have removed the default DHCP server and default Firewall Policy because they referred to “Switch†as the interface.) I am running in NAT mode. I have created 3 interfaces: WAN, DMZ, and LAN on interfaces 10, 11, and 12. For each interface, I have entered an alias, the IP address and subnet mask (x.x.x.x/y.y.y.y) for that interface, and selected Ping for Administrative Access. On the LAN interface I have also selected HTTPS. Interfaces 3 and 4 are setup as heartbeat interfaces but are not in use. The address I used for the WAN interface is one of the static IP addresses assigned by our ISP. I have created a single static default route to the WAN interface using the gateway address that the ISP assigned as our default gateway address (which is the address of the cable modem). On the Fortigate, in Network - Options, I have added our two internal DNS servers and specified a local domain name. I have created two firewall policies to allow all traffic from the LAN to the WAN and from the LAN to the DMZ. Both of these are “Enable NAT†and “Log allowed trafficâ€. On the implicit policy, I have selected “Log violation traffic.†Fortiguard definitions are updating. Users on the LAN can reach the Internet. I have placed a test server (JetDirect print server with a Web administrative interface) on the DMZ network. I have set the server’s default gateway address to point to the DMZ interface on the Fortigate. Users on the LAN can reach the test server using its DMZ address. I have created a Virtual IP entry for the test server as follows: Interface is WAN. A different static IP addresses (not the gateway or interface address) assigned by our ISP is the “External IP address†(leaving the second box on that line blank). The DMZ address of the server is the “Mapped IP Address†(again leaving the second box on that line blank). I did not check the port forwarding box. I have created a Custom Service entry for port 80. It allows ports 1-65535 to get to ports 80-80. (This was following the steps in a tech note. I have also tried “ANY†and the built-in HTTP service as destination services.) I have created a Firewall Policy allowing all hosts on the WAN to connect to the test server using the Custom Service. “Enable NAT†is not checked. “Log Allowed Traffic†is checked. Users on the LAN can reach the server using either its DMZ address or its public address. Users on the Internet cannot see the server. I have changed the logging level to Debug. I don’t see anything of interest in the Traffic log on the Fortigate; in fact we don’t see any outside traffic on the log. Although it doesn’t seem like it would be needed, I have created a second Firewall Policy to allow the test server on the DMZ to access Any/Any on the WAN. I have tried both checking and not checking “Enable NAT†for that policy. “Log allowed traffic†is selected. Reconfiguring the server with a public IP address and moving it to the cable modem (bypassing the Fortigate) works fine. We have tried a lot of variations on this theme. It seems pretty basic but isn’t working. What am I missing? Thank you for any light you can shed into my darkness.
