NEED: To allow an external KMS server (we trust the external IP) to communicate back and forth with our internal server subnet for Windows activation, BUT...
PROBLEM: the KMS server has to see the traffic coming to it from a trusted IP-space. Our firewall external IP is not in their trusted IP-space, and they don't whitelist IPs from other providers. Can I put policies in place to allow the KMS server to see the IPs of our internal servers? If so, how?
(faked IPs below)
KMS Server: 50.100.100.200
Our firewall External IP: 60.120.120.1 (Fortigate 200E, running FortiOS 7.0.9)
Our internal IP subnet: 172.10.10.0/255.255.255.0 (I believe this is considered trusted IP-space, as these are VMs hosted by the same company that has the KMS server)
I should have added, the KMS server only responds on port 1227.
Thanks for the help,
David
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
You may consider to configure IPsec tunnel between your site and KMS site. Therefore, there will be no need in NAT/DNAT.
To solve this problem, you can try adjusting the policy on your Fortigate firewall. Go to the Fortigate firewall configuration settings, go to the firewall rules or policies section. Create a new rule that allows outgoing traffic from the server's internal subnet (172.10.10.0/24) to the KMS server (50.100.100.200) on port 1227. Make sure that the rule has a higher priority than all existing rules that can block traffic. Apply the changes and save the configuration. If that doesn't help, you can get help from kmsauto, which provides help with Office and Windows activation. I'm sure it will work out for you, and good luck.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.