Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Veslaone
New Contributor II

Firewall rule doesn' t work

Hello, Fortigate 100A We have a customer who want to connect on a specific ip via http by the port 81. I did a rule INTERNAL -> specific_ip -> service : TCP_81 -> always -> accept (NAT checked) specific_ip is configured as following : -type : subnet/ip range -ip : specific_ip/255.255.255.255 -interface : wan1 TCP_81 is configured as following : -source port : 1-65535 -destination port : 81-81 Actually, we did a lot of rules, even for this customer, and when we type " http:specific_ip:81" on internet explorer, can' t found the remote site. For the rule wan1->internal a rule is already configured : all -> accept Best regards
3 REPLIES 3
Coldfirex
New Contributor

If you are trying to connect from the outside to an internal server on port 81 then: * remove the fw rule mentioned about internal -> specific_IP * Create a VIP with the ext/int and ports * create a fw rule from outside -> internal selecting your VIP, custom service, no nat I would also get rid of the wan1-> internal rule letting everything in unless there is a VERY specific need/design for this. You will also want to check the order of your fw policies since they are applied top to bottom.
Veslaone
New Contributor II

thank for your answer, but i changed the service by ANY and it works, i dont understand why because my service was correctly configured. It' s maybe a conflict between protocol (http) and port ? I dont know and it works but i' m curious, if you know someone, tell me please
aman_cisco
New Contributor

Hi , Plesae perform the below tests and share the results 1--> Tracret of the url 2--> Test the accessibility after disabling the UTM profile from intrested rule 3--> source is internal or esternal 4--> If possible please test this on any other port , b' coz in some cases port 81 is refered as a port used for several Worms . 5--> Please share diagnose debug flow commands output. Thanks !!!!!
Aman Vijay FCNPS/CCSP/CCSA Senior Security Admin
Aman Vijay FCNPS/CCSP/CCSA Senior Security Admin
Labels
Top Kudoed Authors