Skip to main content
Allwyn_Mascarenhas
New Member
September 20, 2015
Question

Port forward from LAN-1 using WAN-1 internet to LAN-2 using WAN-2 internet on the same for

  • September 20, 2015
  • 10 replies
  • 13298 views

As seen in the diagram is such a network setup possible? The port forwarding works just fine when I try it from an internet connection from somewhere outside my office but says timeout when trying it from the 6.0 network.

 

I am also using policy route to force the 6.0 traffic through wan1. I tried various ways to access the 5.0 network through internal routing itself but that did not work out too. Not sure what i am missing. appreciate all help, thanks.

 

    10 replies

    ede_pfau
    SuperUser
    SuperUser
    September 20, 2015

    Both ways should be possible.

    To reach LAN2 from LAN1, you need

    - the route automatically added by FortiOS for the subnet behind LAN2

    - a policy allowing traffic from LAN1 to LAN2

     

    The policy route will be effective before FOS looks at the regular route. If you force ALL traffic out WAN1 then you won't be able to go this way. Try to exempt traffic destinated to LAN2 from the policy route (e.g. by putting a second policy route on top of it, forcing traffic to LAN2 to ... well, LAN2).

     

    Even if this doesn't lead to a successful connection, traffic should be able to reach WAN2 via your ISPs. Then you would need a policy allowing traffic from LAN1 to WAN1, and incoming traffic from WAN2 to LAN2. Please check that for the first (outbound) policy NAT is enabled!

    Allwyn_Mascarenhas
    New Member
    September 21, 2015

    ede_pfau wrote:

    Both ways should be possible.

    To reach LAN2 from LAN1, you need

    - the route automatically added by FortiOS for the subnet behind LAN2

    - a policy allowing traffic from LAN1 to LAN2

     

    The policy route will be effective before FOS looks at the regular route. If you force ALL traffic out WAN1 then you won't be able to go this way. Try to exempt traffic destinated to LAN2 from the policy route (e.g. by putting a second policy route on top of it, forcing traffic to LAN2 to ... well, LAN2).

     

    Even if this doesn't lead to a successful connection, traffic should be able to reach WAN2 via your ISPs. Then you would need a policy allowing traffic from LAN1 to WAN1, and incoming traffic from WAN2 to LAN2. Please check that for the first (outbound) policy NAT is enabled!

    Hi Thanks for the response.

    Yes the policy route forcing traffic from 6.0 to wan1 doesn't allow traffic to LAN2.

     

    And I need all machines on the 6 subnet to be able to access the the 5.101 ip address either through port forwarding or directly.

     

    So should i put a policy route with dstn 5.101 and drag it above the route for wan1?

     

    ede_pfau
    SuperUser
    SuperUser
    September 21, 2015

    yes.

    Or follow my second suggestion.

    Allwyn_Mascarenhas
    New Member
    September 21, 2015

    ede_pfau wrote:

    yes.

    Or follow my second suggestion.

    Adding a pol route for 5.101 WAS the 2nd solution right. The first not possible since im using pol route for 6subnet -> wan1.

    ede_pfau
    SuperUser
    SuperUser
    September 22, 2015

    A port-forwarding VIP won't let ICMP pass to the internal server as ICMP is not port-based.

    Switch to a non-port forwarding VIP to test if you can ping the server, or connect to the server with the protocol you have allowed.

    This is true for all versions except v5.2.4 where Fortinet changed this behavior: ICMP is now implicitely allowed through a port-forwarding VIP.

    Allwyn_Mascarenhas
    New Member
    September 22, 2015

    ede_pfau wrote:

    A port-forwarding VIP won't let ICMP pass to the internal server as ICMP is not port-based.

    Switch to a non-port forwarding VIP to test if you can ping the server, or connect to the server with the protocol you have allowed.

    This is true for all versions except v5.2.4 where Fortinet changed this behavior: ICMP is now implicitely allowed through a port-forwarding VIP.

    hi i am trying to ping between to interfaces by making to and reverse policies and policy routing. I am not getting what does pinging a VIP mean? Are you thinking i am trying to ping with "ping public-ip:port" ?

     

    i have both subnets on the fgt which use different wan connections. The 192.168.5.101 server is the one i need to access from the 6 subnet. It is accessible through the internet on wan:8888 -> 192.168.5.101 using VIP but doesn't work from the 6 subnet.

    Allwyn_Mascarenhas
    New Member
    September 23, 2015

    got response from fortinet TAC:

    I dont think this is possible, fortigate has the port forwarding ip address fortigate wont sent the packet out to wan1. You may raise up a ticket to have alternative/workaround for this.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!