Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ahmed
New Contributor

Internal Mail server to specific external IP Address

Dear all

I have Fortigate with dual internet lines 

i need to forward traffic from exchange server in the internal LAN  to specific IP address ( Secondary IP Address in WAN1 Interface ).

I created IP Pool ( Fixed Port Range ) .

i used up pool in The policy from LAN TO WAN1 and specify the pool.

set Policy at the top of all policies 

Fortigate ignore the policy completely and apply the next policy on the traffic out from server.

 

Thanks All 

 

 

4 REPLIES 4
GusTech
Contributor II

Ahmed wrote:

Dear all

I have Fortigate with dual internet lines 

i need to forward traffic from exchange server in the internal LAN  to specific IP address ( Secondary IP Address in WAN1 Interface ).

I created IP Pool ( Fixed Port Range ) .

i used up pool in The policy from LAN TO WAN1 and specify the pool.

set Policy at the top of all policies 

Fortigate ignore the policy completely and apply the next policy on the traffic out from server.

 

Thanks All 

 

 

Hi, use policy routes.

Fortigate <3

Fortigate <3
Ahmed
New Contributor

More details please 

NOte : the server in LAN and Need to use NAT to go to the internet 

GusTech
Contributor II

Ahmed wrote:

More details please 

NOte : the server in LAN and Need to use NAT to go to the internet 

You can nat with policys. With policy routes you can force traffic to where you want

The procedure depends on what firmware you are running and what FGT you have. (the smallest has only CLI support in the latest versions ) Go to the System-Config-Features: Activate Advanced routing

Go to : Router-Static Policy-Routes : Create new

Fortigate <3

Fortigate <3
JulianDorl
New Contributor

Looks like a problem with the reverse path check.

 

Try to make a flow debug:

diag debug flow filter (f.e. destination port = dport; source address = saddr etc.) 

diag debug flow show function-name enable

diag debug flow show console enable

diag debug enable

diag debug flow trace start 'Number of Packets - f.e. 15'

 

If you need further help just post the output of the flow debug.

 

 

Best regards

Julian

Labels
Top Kudoed Authors