Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JnascECSI
New Contributor

Outbound VIP Issue

I have a mail server that is using a VIP inbound from Wan1 to Internal IP mappped port to port for mail ports only. Ex. Wan1 10.90.90.9 to Internal 10.10.10.210 The problem i have is that when the traffic goes outbound from the server it is not using the IP of the Inbound VIP IP but that of the internal' s Wan default IP which is 10.90.90.2 Wan1 is setup as 10.90.90.2/255.255.255.240 for that port' s I assumed that when you used VIP that the external IP would be used by the internal device outbound which means outbound on that devive it would be 10.90.90.9 and not 10.90.90.2. I' m just trying to wrap my head around why it' s not going out the same way it' s coming in. Also sorry for posting in the wrong thread did' nt realize it until now that it should have been in the firewall section...
2 x FortiGate 200B 4.2.8 FortiGate 200A 4.2.8 FortiAnalyzer 100C 4.2.4 FortiAP 220B 4.2.7 FortiSwitch 80-POE 4.2.3
2 x FortiGate 200B 4.2.8 FortiGate 200A 4.2.8 FortiAnalyzer 100C 4.2.4 FortiAP 220B 4.2.7 FortiSwitch 80-POE 4.2.3
3 REPLIES 3
jmac
New Contributor

Two-way NAT mapping only works if you do not select the port mapping option in VIP setup. You must create a 1-to-1 IP map for outbound translation to work. If you set up a VIP to map to a specific destination port, then outbound traffic will use the interface IP rather than the VIP address. As long as you don' t use that IP for any other translations, you can control access by setting the service in the firewall policy.
red_adair
New Contributor III

for outbound traffic you just tick NAT and choose a " Pool" that is your /32 addr of your desired new S-IP. -R.
jtfinley
Contributor

Is this not the exact post I just did a few moments before you did? Ironic....
Labels
Top Kudoed Authors