Skip to main content
Contributor III
February 21, 2008
Question

Routing for FTP Server

  • February 21, 2008
  • 32 replies
  • 17799 views
Hi, I have FTP Server in my Organisation, I need FTP server to have Public IP as my vendors will directly FTP to the server and dump the files, also i need local LAN team to access that files, I have Router ethernet connecting to fortigate firewall 800 external interface and Internal Interface connecting to inside network Kindly let me know how do i achieve the same Thanks....Kiran

    32 replies

    rwpatterson
    New Member
    February 21, 2008
    What you need to do here is to create a virtual IP (VIP). This will tell the Fortigate (FGT) what outside IP will be pointed to a private LAN address. Under Firewall > Virtual IP, create a new VIP. It' s prettyr straight forward. What you need to remember is that in the policy, use this VIP definition, not the private IP address of the FTP server. Good luck, and welcome to the forums.
    Contributor III
    February 21, 2008
    Thanks Bob, will check and update you, Cheers, Kiran
    Contributor III
    February 25, 2008
    Hi, I had configured the VIP and policy aswell on my fortigate 800, but when i try to ftp from the outside I am unable to connect to my FTP server, Outside:202.150.105.15 is mapped to Inside:125.120.0.12 policy rule is external interface to inside destination VIP allow FTP services, Pls letme know i missed anything
    UkWizard
    New Member
    March 2, 2008
    This is probably a ftp server config issue, as if you have two NICs it gets messy for routing. Not quite sure why you need two, you say one is " outside" . what do you mean? it cannot be an public address if its behind the fortinet, unless you are using the fortinet in a unsual manner. if you have two nics, you could suffer from default gateway routing issues. make sure you only have one default route ip set on it, and that should be the fortinet. else it wont work. If you could elaborate on the ftp nic setup, i am sure we will all go " aha thats why" ....
    Contributor III
    March 6, 2008
    I have a default IP gateway as my Fortigate IP address on the FTP server, but still i facing a prob, I use 2NIC becaz, fortigate internal interface is connecting to switch, Server One NIC is connected to that switch and another NIC is connected to internal switch, now the problem is from outside am not able to ping or connect to my FTP server,
    UkWizard
    New Member
    March 6, 2008
    so let me get this right, your internal port on the firewall, doesnt actually go into your lan? it goes into a switch, which then only connects to one port on the ftp servers? and the other nic on the ftp server goes to the lan? is that correct? why is it like this?, sounds like a very odd setup to me. Anyway, presuming i got it right above, i am guessing the IP subnets on the two NICs on the ftp server are definatelty in totally different IP ranges?? and that ONLY the nic facing the firewall has the default route set? You must not be using two IPs on the ftp' s NICs that overlap or are on the same subnet range. and also only one default should exist on the ftp server. can you confirm the ip ranges that are on the two NICs?
    Contributor III
    March 6, 2008
    Thanks for reply, basically FTP is in the DMZ area, so it needs 2 NIC' s, both are in differnt network' s, means one NIC having 192.168.1.x, other having the 172.20.9.x, and i have assigned One NIC (192.168.1.x) to fortigate IP as gateway, other doesnot have gateway, Fortigate is also having 192.168.1.x IP address to the internal interface, please let me know for further clarifications,
    UkWizard
    New Member
    March 6, 2008
    so the ftp server has one nic connected to the DMZ and one connected to the internal network? if so, this is very wrong. YOU SHOULD NOT HAVE THIS !! the whole idea of placing web-facing servers in the DMZ is so that if they get hacked, they then cannot use that server to attack internal machines, and thus internal data. The FTP server should only be connected to the DMZ, and the fortinet does the routing for any internal hosts wanting to access the FTP server, via the fortinet. ie; Internal Lan | | Fortinet ------------ DMZ (FTP/Web servers etc) | | Internet via ISP if a server is placed between the DMZ AND the Lan, it is absolutley pointless it being in the DMZ in the first place, as if it got hacked, they would still have access to the internal network. so either move it within the lan (not recommended though) or only have it connected to the DMZ.
    Contributor III
    March 6, 2008
    even in that case, if i place the FTP server in the DMZ area only, i will disconnect from the internal LAN switch, still its not working, my problem is am not able to FTP with the Public IP address which is mapped in the fortigate (VIP), its not working,
    UkWizard
    New Member
    March 6, 2008
    do some packet sniffing from the command line, either from the status screen cli console, the serial port, or via ssh/telnet. do the following commands and then test the ftp; # diag sniff packet external ' port 21' look to see whether you see the incoming requests of packets. from the requesting clients IP address then do the same, but on the dmz port, like so (example presumes dmz port is called dmz, and not dmz1); # diag sniff packet dmz ' port 21' test and see whether you see packets being listed, if so, then the VIP is working but the FTP server must have issues. If the first test fails, then the ftp request isnt even hitting the fortinet in the first place. if the first works, but the second test doesnt show anything, there is something wrong somewhere on the fortinet, either a dodgy firmware build, a bug, or a config issue like network masks or routes/policy routes.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!