Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
YorkshireMatt
New Contributor

Internet access crssing to route VDOM

I am sure this is simple but for whatever reason I am unable to find correct solution.

 

We have multiple VDOM including one for root, and all VDOM have inter VDOM links to root. Internet access is from root, however the only way I seem to be able to make bi-directional traffic work is to use two external IP addresses.

Example: 192.168.1.1 has an IP-Pool address of 62.10.10.1 which is used within the client VDOM policy, traffic routes via a static routeto 0/0 via the inter VDOM link and a policy in root allows traffic to the internet without further NAT.

Traffic coming in to 192.168.1. has to come in via 62.10.10.2, which is a VIP in root that maps to 192.168.1.1, so incoming traffic is reversed NAT'd in root and then ushed across the inter VDOM link in to the client VDOM where it is sent on to the server.

I havr read technical notes about using the CLI to modify the VIP set nat-source enable oand not having an IP-Pool or somehing similar but nothing seems to work.

Any suggestions or pointers appreciated.

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors