FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
npaiva
Staff & Editor
Staff & Editor
Article Id 342229
Description

 

This article describes possible reasons why sources may not be seen for a VIP under Fortiview Sources, when protecting a website/service with the FortiGate.

In the following example, a service running on a Webserver behind the FortiGate is accessed. It can be accessed via the internet from a device with Public IP 20.73.17.183, but FortiView sources shows nothing matching this IP:

 

not-showing.png

 

Scope

 

FortiOS.

 

Solution

 

The Flow for this traffic is as follows:

 

Client -> Internet -> FortiGate WAN -> Webserver.

 

Results are not obtainable because the WAN1 interface of the FortiGate has the role 'WAN' selected:

 

role.png

 

By design, results will only be seen under FortiView Sources if the source interface is set to 'LAN' or 'Undefined'.

Changing the Wan1 interface role to 'Undefined' makes it possible to see the source under FortiView Sources:

 

showing.png

 

Contributors