Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NJAB
New Contributor

Fortigate 100F Routing

Hi,

 

I am new to Fortinet devices and routing in general and have a change to apply, we have a user that moved into the office locally recently from remote work needs to access an address, https://gis.********.co.nz/portal/home/index.html  and this leads to a local server onsite. There is an SSL cert applied for this server. I am assuming that there need to be a route to allow for the traffic going to that address to still work, where can I start looking at this or if someone can point me in the right direction it would be great.

 

Kind Regards,

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

If the Web server is internal to your FGT, there must be a VIP policy for the public IP access from outside to translate/DNAT to the server's local IP at the FGT. Then you need to allow internal users (inside of the FGT) to the same outside public IP then "hairpin" back to get to the internal server by following the same VIP policy. 
You can follow this KB to set it up. If you're not familiar with CLI, you need to familialize yourself to it first.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-Hairpin-NAT-VIP/ta-p/195448

Toshi

ebilcari
Staff
Staff

If both the server and the host have their gateways on the FortiGate, routing configuration is not required. You should verify that the DNS server used by the host can resolve the server's private IP address. Additionally, a firewall policy must be created to allow traffic between the host subnet and the server.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors