Skip to main content
Contributor III
September 30, 2008
Question

Port forwarding with dual Wan

  • September 30, 2008
  • 7 replies
  • 4127 views
Hello, I' ve run into another problem with our Fortigate 60b (FortiOS 3.0 MR7). We have two internet connections from different ISP' s in our office. These are connected to WAN1 and WAN2. Now we want to forward the HTTPS port (443) to two different IP' s in our LAN using one WAN interface for each PC in the LAN. Here is an example which should better describe the problem: WAN1_IP:443 -> WAN1 -> PC1 WAN2_IP:443 -> WAN2 -> PC2 Whenever I try to solve it with VIP' s, I get the error message: " Duplicated entry found" . Can someone help me to solve that problem? Or is that impossible? With best regards.

    7 replies

    rwpatterson
    New Member
    September 30, 2008
    Sounds like it should work... They are different. Do you have any other VIPs terminating at either of those 2 units without port forwarding? This will stop it from working. Once you forward an entire IP, you can no longer break out ports to that same IP. You have to create groups of VIP port forwards (and group them together maybe) to do the same job thereafter. Hope this helps
    Contributor III
    September 30, 2008
    No, I use VIP' s only to forward ports. Here is how it looks in the overview, perhaps it will help a bit: 1. VIP:
    rule1 wan1(Internet)/0.0.0.0 443/tcp xxx.xxx.xxx.xxx 443/tcp
    2. VIP (how it should look like):
    rule2 wan2(arcor)/0.0.0.0 443/tcp xxx.xxx.xxx.yyy 443/tcp 
    UkWizard
    New Member
    September 30, 2008
    i have seen this before, i think its a bug with the GUI somewhere. Think i was creating address entries though. Cannot remember exactly what the cause was, sure it was zone related, or the length of a zone name. something odd like that. sorry i cannot remember exactly. Do you use zones?
    rwpatterson
    New Member
    September 30, 2008
    Show us the output of:
    > show firewall vip
    Contributor III
    September 30, 2008
    i' m not sure what you mean with zones, but i think we don' t use something like that... if i put in put in an external adress in one of these 2 than it works... but both should be accessible from any external ip..
    rwpatterson
    New Member
    September 30, 2008
    There' s the deal. Port 443 can only go to an inside device once. You cannot VIP point port 443 from both outside interfaces (as far as I can tell, without some hairy trickery).
    Contributor III
    September 30, 2008
    really? i thought because the external IP' s from the two WAN interfaces are different, it would be no problem to forward the same port to two different internal clients... we really need that for our setup here..
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!