Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Austin_M
New Contributor II

Hair pin nat config

Hi Guys,

 

I need to allow guest users access to my DMZ mail server using the public natted IP and not the real DMZ private IP.  

From what I have read on the forums about this, it seems I need to configure hair pin nat for this to work. Could someone please let me know the settings need to be done for it to work..

 

device : Fortigate 311 B

 

Details of traffic flow :

 

Source interface  -  Port1 ( Internal )

Source Address - 10.0.135.0/24

Destination interface : Port5 (DMZ)

Destination Server real IP : 192.168.100.10

Wan 1 -  94.10.12.1

Wan 2 - 94.10.13.1 

VIP details :   (Wan1) 94.10.12.2 ->  192.168.100.10

 

Wan1 to Port5 policy with destination as VIP is already configured and works fine for hosts on the internet.

 

There is a policy route configured to route internet traffic from 10.0.135.0/24  forcing it to go out through Wan2.

 

Thanks,

Austin

 

 

 

 

2 REPLIES 2
Dipen
New Contributor III

 

Technical Note : How internal users can access internal resources via an external VIP (public IP address)

http://kb.fortinet.com/kb/documentLink.do?externalID=FD33976

 

 

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
vinisantos_FTNT

Have you tried the configuration in this article? http://cookbook.fortinet....air-pinning-fortigate/

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors