Skip to main content
georgeWong
New Member
March 22, 2022
Question

VIP hairpin access

  • March 22, 2022
  • 13 replies
  • 8698 views

Hi , these days i am studing FGT, i am confused at this case-

The VIP is set extintf 'port10', but now 10.10.10.2 accesses 10.10.10.100 port 21, the packet is entering in port9, not in port10,can this activate the DNAT(VIP)?How the FGT works at this scene?

I searched many documents but no answer.  Thank you in advance!

georgeWong_0-1647918516860.pnggeorgeWong_1-1647918555943.png

 

georgeWong_2-1647918883660.png

 

13 replies

Patterson
Staff
Staff
March 22, 2022
georgeWong
New Member
March 22, 2022

Thanks Patterson, but did not not answer my question yet. Why the traffic goes in port9 can activate the DNAT'ed(VIP)? Then  the traffic goes to port9, why "Allowed by policy-2 SNAT"? I did not see any ’NAT enabled' at policy-2.

ede_pfau
SuperUser
SuperUser
March 22, 2022

Is the VIP defined on the 'any' interface or on 'port10'?

The SNAT issue is interesting. Hard to tell if the config is missing from your post (VIP, policy)...do you use Central NAT?

Debbie_FTNT
Staff & Editor
Staff & Editor
March 23, 2022

Hey ede, George,

-> from the screenshot with configuration snippets, the VIP is configured with extintf port10, correct?
-> you have two policies, 2(from port10 to port9, with VIP as destination, no NAT) and 1(from port9 to port10, with NAT to interface IP enabled)?

 

Technically, traffic from internal host 10.10.10.2 to 202.106.1.100 (public IP of VIP) would initially match policy 1 (go from port9 to port10 and have NAT applied) and then immediately match policy 2 (VIP), right?

It looks to me a bit as if FortiGate is applying both policies at the same time (matching VIP based on policy 2, applying NAT based on policy 1).

For testing, can you turn off NAT in policy 1 and check if the 'SNAT' bit in debug goes away?

 

Your setup does mirror scenario 1 as outlined in the KB shared by Patterson:

https://community.fortinet.com/t5/Fortinet-Forum/VIP-hairpin-access/td-p/207277

georgeWong
New Member
March 24, 2022

Hi Debbie, settings were as you said. I think the Policy-2 SNAT is for traffic to Internet.

"traffic enters and leaves FortiGate via the same interface. This causes FortiOS to automatically perform SNAT, even if NAT is not configured in the firewall policy."--This automatically SNAT will be for the hairpin traffic I think.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!