Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Configuration of DMZ

I am having trouble setting up the a DMZ. I believe the confgiguration is correct but I can not able to get out onto the internet from the DMZ. Internetcoms into wan1 Internal system connects to several computers. DMZ only connects to one computer. I tried two systems on DMZ. both are able to connect on the working network fine. I configured the network DMZ interface to manuel and options for DMz to forward DNS The Primary DNS is my ISP SERVER same as my WAN I created firewall policy to allow wan1 to DMZ DMZ to Wan1 wan1 to internal All are wide open
9 REPLIES 9
rwpatterson
Valued Contributor III

Make sure NAT is enable on any policy facing the Internet. Private IP addresses are not able to be routed across the Internet. If that doesn' t help, run a traceroute from the command prompt and see how far your traffic gets before it dies.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
UkWizard
New Contributor

If the above doesnt resolve it, as you say you only have one host, i am presuming that its a direct cable to the dmz port, is it? and if so, check the duplex settings and cable in case the link between the DMZ port and the servers lan interface isnt quite working properly.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

First thanks for the help. I guess I should have given the model. It is a FGT 60ADSL. Nat is enabled on the policies. Running a tracert does not go anywhere. Nor can I ping anything but the loopback I do have a cable running direct from the fgt to the computer. DMZ port to NIC card on CPU I am not sure what you mean by checking the duplex setting because I believe that this unit does not have duplex settings. I have tried other cables and I did at one time try a crossover cable. The ip adress the computer gets as configured 169.254.231.54/255.255.0.0
rwpatterson
Valued Contributor III

What that IP address is, it' s the Microsoft auto configure address (range). This basically means that DHCP is turned off (or is not working correctly) on the DMZ port and that the work station does not have a valid IP address. No communication will take place on that port until this is resolved. Hard code in a valid IP address and see if the situation changes any. Let us know.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

I am not sure where I should be hard coding the IP address. I tried it on the machine itself and then on the interface of the DMZ. neither work but I am not confident I did this step correctly Thanks
rwpatterson
Valued Contributor III

What is the DMZ ip address?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

orginally it was10.0.0.1/0.0.00 then I made it 24.221.30.159/255.255.255.0 after the above request
rwpatterson
Valued Contributor III

Your device should then be 24.221.30.x with the DMZ port configured as the default gateway. With this setup, you should be able to at least ping the DMZ port on the FGT. If your policies are then correct, you should be allowed further out. Personally, I would avoid using IPs in this range, because they are reserved for public IP addresses for ISPs using cable modems. (See public RFC 3330 for more on this) The 10.0.0.0 IP address range would have been suitable.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

Thank you for your help and information. I did put the ip back to 10.10.10.1 as you suggested. I did not have the DHCP server set up correctly on the DMZ I put in the 10.10.10.1 as my gateway as you suggested followed by my DNS 23 in the advance DHCP server
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors