Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Pavel
New Contributor

Forwarding Exchange traffic

Good day to all! Last thing that I didn' t resolve with my FG 100D is Exchange traffic. I have WAN link load balancing with 3 physical ports used. 1 ISP with 2 connections (2 ip ranges with different gateways) and 1 reserve ISP. First ISP is main and all my websites and services are published and using its ips. One of this service is Exchange. I need to forward all exchange traffic using just one ip as a gate from first ip range (it' s WAN1 port ). How can I do this? I tried to do this by VIP with portforwarding tcp 25, but it doesn' t works correctly. Incoming traffic started to come but outgoing traffic sometimes goes through other ips of both ip ranges.
2 REPLIES 2
FortiAdam
Contributor II

Hi Pavel, I believe the way to accomplish this is via an IP pool on your outgoing NAT rule for your Exchange server. If you don' t have a separate policy for this already, create one with just your exchange server as the source. Enable NAT and choose to use dynamic IP pool instead of use destination interface address. You can create your IP pool by navigating to Firewall objects > Virtual IPs > IP Pools. Be sure to order your policy correctly! If you are using a VIP without port forwarding all of your outgoing traffic should also use that same IP but since in this case you are using port forwarding you will have to utilize an IP pool for your outgoing traffic. Am I way off here guys or is this pretty close?
Pavel

Hello FortiAdam, yes, you were quite right. I did it with the help of ip pool. The problem was hidden in features... :) Again and again. By defaul central NAT is disabled. I' ve activated it, then did ips and ports matches, created outgoing policy, put it in priority higher than local trafic>external net policy and it worked. Anyway thanks for your feedback!
Labels
Top Kudoed Authors