Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

todd
New Contributor

Freepbx Fortiguard 200e - Anyone get this working?

I've got a Fortiguard 200e with v6.0.1 and I'm trying to get a FreePBX server on the LAN port to work. I'm unable to receive incoming calls. My SIP provider indicates that when they send a call our way, our server is unresponsive. We are running FreePBX v13.0.195.4. I'm able to make outgoing calls without issue. 

I've setup two IPV4 policies as follows:
Incoming Interface: WAN
Source Address: All
Outgoing Interface: LAN
Destination Address: Address object (10.0.1.26)
Service: SIP (TCP 5060-50601)

Incoming Interface: WAN
Source Address: ALL
Outgoing Interface: LAN
Destination Address: Address object (10.0.1.26)
Service: Custom (UDP 10000-20000)​

Has anyone been able to get a FreePBX server working with Fortiguard? So far I'd have to say no but I've got my fingers crossed.

------------------------------
Todd [LastName] [Designation]
IT Manager
[CompanyName]
[City] [State]
[Phone]
------------------------------
2 REPLIES 2
PC
New Contributor III

Did you setup a VIP for the inbound NAT setup? 

Using virtual IPs to configure port forwarding - Fortinet Cookbook

Fortinet Cookbook remove preview
Using virtual IPs to configure port forwarding - Fortinet Cookbook
This recipe demonstrates how to use Virtual IPs (VIPs) to configure port forwarding on a FortiGate unit. This configuration allows users on the Internet to connect to your server protected behind a FortiGate firewall, without knowing the server's internal IP address and only through ports that you choose.
View this on Fortinet Cookbook >





------------------------------
Peter [LastName] [Designation]
Enterprise Engineer, Networking
[CompanyName]
[City] [State]
[Phone]
------------------------------
todd
New Contributor

Apparently we didn't need the NAT settings. We only needed the port forwards. Once we got that figured out, it all works.

------------------------------
Todd [LastName] [Designation]
IT Manager
[CompanyName]
[City] [State]
[Phone]
------------------------------
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.