Skip to main content
ephemeric
New Member
February 8, 2019
Question

Virtual Server to Virtual IP

  • February 8, 2019
  • 0 replies
  • 1855 views

Hi,

 

I have a network interface (IPsec tunnel interface) with 10.212.135.1/32 address.

 

I created a Virtual IP object of type static NAT:

  External IP Address/Range: 10.212.135.1 - 10.212.135.1

  Mapped IP Address/Range: 10.0.15.201 - 10.0.15.201

  Port forwarding:

    Protocol: UDP

    External Service Port: 5514 - 5514

    Map to Port: 5514 - 5514

 

Now, from 172.19.119.100/32 via the IPsec tunnel to 10.212.135.1:5514 UDP works as this is forwarded to 10.0.15.201:5514. All good.

If I now try to change the Mapped IP Address/Range to 10.0.15.210 (which is a Virtual Server with three real servers of 10.0.15.201, 202, 203) this breaks.

I get "denied by policy 0 dropped".

 

Is this possible, a valid use case? I tried adding another policy to allow to the Virtual Server and destination All but no dice.

Please advise if any further info is required.

 

Thank you.

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.