Dear all
I have Fortigate with dual internet lines
i need to forward traffic from exchange server in the internal LAN to specific IP address ( Secondary IP Address in WAN1 Interface ).
I created IP Pool ( Fixed Port Range ) .
i used up pool in The policy from LAN TO WAN1 and specify the pool.
set Policy at the top of all policies
Fortigate ignore the policy completely and apply the next policy on the traffic out from server.
Thanks All
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Ahmed wrote:Dear all
I have Fortigate with dual internet lines
i need to forward traffic from exchange server in the internal LAN to specific IP address ( Secondary IP Address in WAN1 Interface ).
I created IP Pool ( Fixed Port Range ) .
i used up pool in The policy from LAN TO WAN1 and specify the pool.
set Policy at the top of all policies
Fortigate ignore the policy completely and apply the next policy on the traffic out from server.
Thanks All
Hi, use policy routes.
Fortigate <3
More details please
NOte : the server in LAN and Need to use NAT to go to the internet
Ahmed wrote:More details please
NOte : the server in LAN and Need to use NAT to go to the internet
You can nat with policys. With policy routes you can force traffic to where you want
The procedure depends on what firmware you are running and what FGT you have. (the smallest has only CLI support in the latest versions ) Go to the System-Config-Features: Activate Advanced routing
Go to : Router-Static Policy-Routes : Create new
Fortigate <3
Looks like a problem with the reverse path check.
Try to make a flow debug:
diag debug flow filter (f.e. destination port = dport; source address = saddr etc.)
diag debug flow show function-name enable
diag debug flow show console enable
diag debug enable
diag debug flow trace start 'Number of Packets - f.e. 15'
If you need further help just post the output of the flow debug.
Best regards
Julian
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.