Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MaeIstrom
New Contributor II

Fortigate is blocking traffic to another DNAT setup

I have a server running multiple services behind a modem that uses port forwarding to redirect ports on the public ip to an internal ip. So for example homeserver.ddns.net:8123 forwards through to 192.168.1.1:80. This works fine for all computers except the ones behind a fortigate device running FortiOS v7.0.12 (GA). The only relevant firewall rule on the fortigate is one say all traffic from the internal device to the external device should be allowed and NATed. The machines on the internal network can connect to any other ip or port on the internet just not the ones behind my modem, they just timeout. Although I do notice there's an option to preserve the source port that is currently disabled. Would that help or is there anywhere else that this type of traffic is being blocked?

3 REPLIES 3
MaeIstrom
New Contributor II

So just did a traceroute from one of the machines and the first hop was the fortinet's internal IP, the second was something other than its public IP. Same subnet but where I would expect to see 44.44.44.44 it's 44.44.44.1. Now my boss is talking about CGNAT which is possible I guess but I could've sworn they had a static IP. Plus the fortinet itself forwards proxmox and ssh ports to an internal IP and that has never not worked. 

funkylicious
SuperUser
SuperUser

hi,

from my understanding the DNAT is performed on another device not directly on the FortiGate.

on the FGT is there any traffic/configuration done for this DNAT to work, like a VIP or something or firewall rules ?

a diagram of the setup would help understand better the setup and where to tshoot the problem.

"jack of all trades, master of none"
"jack of all trades, master of none"
nevan
Staff
Staff

Preserved source port is very likely the fix the NAT session handling issues, often fixes this because the modem’s DNAT expects the original source port. Also check that strict source checking is disabled, as FortiGate may drop the return traffic otherwise. 

To troubleshoot in detail, open a TAC ticket as well but be informd that the 7.0 FortiOS version is out of support at the moment. Please try also upgrade to a supported version including engineering support like 7.4, 7.6 and 8.0.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors