Skip to main content
zeno
New Member
November 7, 2018
Question

open ports in fortigate

  • November 7, 2018
  • 2 replies
  • 3546 views

Hi everyone

 

i have been asked to move production server to dmz another range 

Actual Navision production web server is located on p-web-nav01(192.168.16.0/24)they want to move  it to DMZ (192.168.18.0/24)

We have two services there, one is the NAV Web Client Service and the second is NAV Help Server. Is it possible to have this server accessible from internal network on port 49000 ??

Tasks :

1- open port 443 to internet (all navision users should be able to connect ) 

2- opens Communication on port HTTP: 49000 to Internet and Internal Network (all nav Users should be able to connect)

3- opens communication between NavServer  and WebServer  - 7076

 

can anyone help me with this i don't wanna make any mistake when making the changes 

 

Thanks in Advance 

    2 replies

    sw2090
    SuperUser
    SuperUser
    November 7, 2018

    VIP + policy will do this for you. There is Cookbook articles on this...

     

    Beware: if you redirect 443 you will not be able to https access the FGT from outside anymore unless you change the port the fgt uses.

    zeno
    zenoAuthor
    New Member
    November 7, 2018

    so what I have to do is :

    1- virtual ip:  100.82.90.86_192.168.18.62_443 (tcp: 443 --> 443)

      ipv4 policy:  100.82.90.86_192.168.18.62_443 /  / services https , tcp_8443

    2- virtual ip: 100.82.90.86_192.168.18.62_49000 (tcp: 49000 --> 49000)

    ipv4 policy: 100.82.90.86_192.168.18.62_49000 / / services 49000

     

    please correct me if i'm wrong

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!