Description | This article describes how VIP/DNAT lookup is done in FortiOS and how this may affect communication. |
Scope | All FortiOS versions. |
Solution |
FortiOS by design will do VIP lookup before policy lookup. If in case multiple VIPs are using the same external IP and port, matching incoming traffic used in different policies, if the VIP used in the policy allowing traffic is not the one selected by FortiOS in VIP lookup, traffic will be dropped.
If having multiple VIPs mapping to the same external IP: Without port-forwarding, only the first VIP will be matched, for any traffic destined to the external IP. This will cause traffic for policies with the other VIPs applied not to be matched.
With one or more VIPs with port-forwarding, make sure to place those above VIPs without port-forwarding enabled, otherwise, traffic will match the first VIP therefore the policies with the other VIPs will not be matched.
Related Documentations: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.