Skip to main content
dpsguard
New Member
March 12, 2021
Solved

Return Traffic Public IP for Server

  • March 12, 2021
  • 2 replies
  • 3814 views

Hello Experts,

 

Can someone please confirm that if we have a regular VIP with an Public IP address, other than the Firewall external interface IP, will return traffic from the exposed server will use the same Public IP from the VIP? If not, do I need to create an IP pool with the same Public IP and then use that to NAT Internet bound traffic from server?

 

Also what IP will be used by server if it initiates the traffic out to Internet in case of exposed server with VIP setup?

 

Thanks

    Best answer by PerthNSE

    G'day.

     

    The VIP will be used for outbound traffic if you are not using port forwarding. If you are only applying inbound VIP to a specific range of inbound ports then only traffic that matches that same traffic will use the VIP on outbound. 

     

    i.e. You will need to create an outbound IP pool policy for all traffic to use the VIP address unless you have the VIP policy forwarding all traffic to the destination.

     

    Hope this clears things up!

    2 replies

    PerthNSE
    PerthNSEAnswer
    New Member
    March 12, 2021

    G'day.

     

    The VIP will be used for outbound traffic if you are not using port forwarding. If you are only applying inbound VIP to a specific range of inbound ports then only traffic that matches that same traffic will use the VIP on outbound. 

     

    i.e. You will need to create an outbound IP pool policy for all traffic to use the VIP address unless you have the VIP policy forwarding all traffic to the destination.

     

    Hope this clears things up!

    dpsguard
    dpsguardAuthor
    New Member
    March 12, 2021

    Thank you so much for your advice and confirmation. I was confused as to what will be the outbound Public IP if the server in question initiates the traffic. And as per your clarification, if it is 1:1 map, then it will use the same VIP. For port forwarding situation, we will need to create an IP pool using the VIP as the only address in that pool and apply that to the outbound policy for NAT to this VIP pool. If this is not done, then server will use the regular interface NAT if that is set up for the subnet the server is on.

     

    Appreciate again.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.