I would like to ask some questions about "virtual servers" in FortiGate. I deployed my firewall on azure with three subnets:
1) External Subnet: 192.168.200.0/24
2) Internal Subnet: 192.168.90.0/24
3) Protected Subnet: 192.168.100.0/24
My two database servers are deployed on Protected subnet 192.168.100.10 and 192.168.100.11. They are listening Port TCP 1521. I would like to load balancing these two servers in FortiGate. The virtual ip will be 192.168.100.240.
My configuration cannot route TCP port-1521 from client to this virtual Ip. I can access from client VM to each server with TCP port 1521. Any suggestion?
My firewall Rules:
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Can yry enable all log in the policy (and in the implicit deny policy) and check if you see any related traffic log?
Yeah, but no traffic is found.no deny log found.
Client's packets are probably not reaching FGT.
You can confirm with packet sniffer as suggested by @hbac .
If this is confirmed you may check routing from client to FGT.
When I do WAN to LAN virtual server configuration, it was working well. But for Lan-to-Lan virtual server configuration, the traffic could not pass to this virtual lan ip.
I have two database server in lan network (192.168.100.4 and 192.168.100.5) and then i created virtual server with virtual ip 192.168.100.240 and put these two server into the backend. But the Lan client (192.168.100.0/24) cannot access the virtual ip address.
This Firewall is running on azure.
I did enable deny policy.There is no traffic flow through.
Hi @johnie,
You can run packet sniffer to see if the traffic even hits the FortiGate: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Using-the-FortiOS-built-in-packet-sn...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.