Problem - firewall rule with virtual IP to internal FQDN
Fortigate 81F
FortiOS 7.0.16
Hi all, I'll see if I can explain this clearly.
We have an external DNS A record webserver.com that points to one of our public IP addresses 1.2.3.4.
On the Fortigate we have a Virtual IP that points to an FQDN internal DNS A record webserver.internal. webserver.internal has a private IP address 192.168.1.1.
On the Fortigate we have a firewall rule that permits access to the Virtual IP on port 443.
Internally we have a Windows failover cluster service that can change the IP address of webserver.internal to another private IP on a different subnet 192.168.2.1.
Issue: when webserver.internal is pointing to 192.168.1.1 everything works fine. When webserver.internal is pointing to 192.168.2.1, there is no longer any external access. Internal access continues to work fine.
After the IP address of webserver.internal changes, this change is successfully reflected on the Fortigate. On the Fortigate if I go to Addresses, the webserver.internal record successfully resolves to the new IP 192.168.2.1 (it has a 5 minute ttl). The Fortigate can successfully ping and traceroute to the new IP.
This sounds like it might be an internal routing issue, but from the moment the IP for webserver.internal changes to 192.168.2.1, there are no longer any hits recorded on that Fortigate firewall rule, the only reference to that virtual IP is in the the implicit deny, and that is for legitimate denies (i.e. attempts other than HTTPS). The external DNS records are not changed at all. Once the IP for webserver.internal changes back to 192.168.1.1, everything works fine again.
Has anyone encountered this issue before and has hopefully resolved it?
thanks
j
