not able to access internal servers IP using Virtual IP. firewall access rules also in place. still facing challenge...
Hello
Hello ArviRaja,
Thank you for reaching out. There are a lot of information that needs to be reviewed here for proper recommendations like the cofig of the interfaces, VIP, firewall policy. If you are looking for troubleshoot steps only then best to start with 2 sinffer commands in separate simultaneous cli sessions to monitor the traffic as well as another session with debug flow output:
- sinffer:
# diag sniffer packet any "host x.x.x.x" 4 -------- you can run one sniffer were the address is the external ip and another sniffer for the real ip of the internal server
- debug:
diag de reset
di de flow filter addr x.x.x.x
di de flow filter port <dst port if it is a custom port>
di de flow trace start 10
di de console time en
di de en
Otherwise I would recommend opening a ticket with support if there is a valid support contract.
Thank you,
saleha
FG30E ver 6.2.9
forticare ad fortiguard licenses expired on FG30E
This feature doesn't require a license.
FG30E ver 6.2.9
If it is VIP, Make sure NAT is disabled on the policy.
Hi @ArviRaja,
Is it a new configuration? Please collect debug flow to see why it is not working. You can refer to https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Regards,
User | Count |
---|---|
1923 | |
1144 | |
769 | |
447 | |
279 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.