Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Christian_89
Contributor III

FortiWEB Problem https

Hello everyone

I have the following problem with a customer.
The customer customer has an Exchange on-Perm.
For OWA access, this runs through the FortiWEB VM.
Now the problem is that this connection does not work again and again. When I check the FortiWeb I always get Connection Timeout from the Exchange.
But if I do the whole thing with the Fortigate, it works without any problems.
If I change the confg. Exhibit and readjust with us It works perfectly.

Does anyone have any tips or ideas as to what could be the issue.

Thank you very much for your help

Greeting

Christian

7 REPLIES 7
AEK
Honored Contributor II

Hi Christian

 

The issue can have many reasons.

 

First of all you should check traffic logs on FWB, FGT & web server to see if traffic is denied or missing somewhere.

 

Then try detect if the issue is in the front-end or in the back-end to reduce troubleshooting surface.

- ping & tracert from your PC to your FWB VS

- ping from FWB to back-end web server port 80/443

- telnet from your PC to your FWB

- telnet from your FWB to your back-end server port 80/443

 

You can also use packet sniffers to check if any traffic.

- Use tcpdump or wireshark on the web server to check if any traffic is coming from FWB

- Use diag sniffer on FGT & FWB to check if the sent packets get any response from the other side

 

Also you can try download & install a new FWB VM from scratch. Verify the checksum before installation.

 

AEK
AEK
jintrah_FTNT
Staff
Staff

Hi,

 

We should check why there is a connection timeout from FortiWeb to Exchange. Is the exchange gateway not pointing towards FortiWeb? If not, the traffic from FortiWeb should be NATed with FortiWeb interface IP address so that Exhange servers can send the traffic back to it.

 

Best regards,

Jin

Christian_89

Hi Jin

No, the gateway is from the Fortigate.

jintrah_FTNT

Ok about the gateway of exchange. So the return traffic from Exchange is trying to go out to internet directly from FortiGate? Or is Source NAT enabled on FortiWeb so that return traffic from exchange reaches FortiWeb? This should be checked as you had connection timeouts.

 

Best regards,

Jin

Christian_89

Thank you for the information.

I'll adjust that today and see if it improves.

Christian_89
Contributor III

I tried the whole thing with a new address. I have no problems with this one.
Would you suggest if I reinsert the original address to make everything new?

jintrah_FTNT

Hi,

Before reinserting the original address, make sure it is not used or defined anywhere in the setup or in any configurations. Otherwise, it should just work like the new address.

 

Best regards,

Jin

Labels
Top Kudoed Authors