Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
edgeman
New Contributor

Issue with VIP

Hi Everyone,

 

I have a problem that someone may be able to help me with / point me in the right direction. I come from a Sonicwall background so this may just be terminology that is throwing me :)

 

I've searched the forum and tried a few things but can't get past my VIP issue, namely that the port 25 VIP that I set up is not sent on to the mail server.

 

I have set up a VIP, a policy, according to the cookbook, on my 60C (4.0) with an external ip of 0.0.0.0 (it's dynamic / dhcp delivered), internal IP of my mail server (private net), port forwarding on and TCP port 25 specified in the external and map to port fields.

 

My policy has the source interface as wan1, source address "all", destination interface of internal and destination address my VIP. Schedule is always, service is SMTP and Action is ACCEPT (and no NAT).

 

Problem is nothing gets through. I can telnet from the firewall (SSH) to the mail server on port 25, but when I try it from an external internet host I see lots of "wan 1 in" records (diag sniffer packet any "tcp and dst port 25" 4) but nothing ever out to the mail server.

 

The mail server is on the same subnet as the firewall's internal interface, and the firewall is running in NAT mode. I can ping from the mail server to the external internet test host, so connectivity seems to be fine.

 

Thoughts?

 

Thanks!

 

12 REPLIES 12
ede_pfau

If you sniff on the port where the server is attached to, do you see any incoming traffic?

I'd suspect so.

If not, check your default route. If so, you should see outgoing traffic BUT with a private source address. You have not enabled NAT in the policy. Only in more recent versions of FortiOS the VIP will automatically source-NAT reply traffic to the external IP address, and in v4.2 this might not have been implemented yet.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
rpedrica

Something you need to check is whether the mail server is pointing to the FG for gateway - if it's not then a VIP will never work ( ie. asymmetric routing )

 

Regards

edgeman

 Sorry for the delay everyone. The solution was an upgrade of the firmware. I upgraded to 5.2.5, after the registration of the device was transferred over.

 

Thanks for your help!

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors