Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

LAN --> DMZ Access Problem

We are using FortiGate 300A (FG300A-3.00-FW-build726-080716). We are using 2 ports (PORT5=LAN & PORT3=WAN). Now I have configured one more port PORT6=DMZ. IP Addresses given to them are as below: PORT5(LAN) = 192.168.16.0/255.255.255.0 PORT3(WAN) = 125.x.y.z PORT6(DMZ) = 192.168.50.0/255.255.255.224 Now I have a FTP Server in DMZ Zone. I added a Firewall Policy to allow traffic originating from LAN to DMZ. But, that is not working. LAN-->WAN / WAN-->LAN / WAN-->DMZ is working fine. But, LAN-->DMZ is not working. What might be the reason? I have tried adding a Static Route for 192.168.50.0/255.255.255.224 subnet, but that is also not working. Thanking You in Advance. Regards, Denis Dudhia
4 REPLIES 4
MasterBratac
Contributor

Do you perhaps have policy routes configured, that route the traffic to the wrong port?
UkWizard
New Contributor

Check the mask on the DMZ server to ensure its correct, and that it is in the same range as the firewall. Also, Do you have NAT enabled on the WAN -> DMZ policies? If so, turn them off and see if they still work, if they do not, then it will be the DMZ server doesn' t have the default gateway set properly.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Thanks for your valued reply. No policy routes have been configured. Subnet Masks are proper and NAT is not enabled in Firewall Policy. But, still I am not able to access the Server in DMZ. However I am able to ping the DMZ Port from LAN. What are the basic steps required to configure a DMZ and to give access from LAN to DMZ? Thanks in Advance.. Regards, Denis Dudhia
UkWizard
New Contributor

You just need a LAN -> DMZ policy with nat disabled. But if you can ping the DMZ IP of the fortinet, it sounds more like the server you are connecting to either has a firewall, or doesn' t have the fortinet as its default gateway
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors