Hello,
one thread closed, next opened ;)
We're trying to hair-pinning some internal Server, which are in the DMZ and accessed from the LAN over the VIP-IP.
Unfortunately, the official cookbook guide from fortinet couldn't help me.
Which rules I have to set in the fortigate for this doing?
How is you VIP setup? If you leave the interface set to ANY, you do not need hair-pinning. The VIP address will be available from both the public facing and internal interfaces. You can then create a rule allowing internal addresses sourced from the internal port to the destination VIP on the DMZ interface.
HTH
d
Thanks for your help!
Hey, I fixed it. For this you need a Policy Route and in this policy you have to stop all policys from dmz to lan. Button is "Stop policy routing"
Now i can connect to a forwarded lan server port from dmz
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.