Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
2017-04-28 10:13:15 id=20085 trace_id=137 func=print_pkt_detail line=4793 msg="vd-root received a packet(proto=6, MailserverIP:443->192.168.201.3:52631) from internal. flag [S.], seq 1020708212, ack 2966908897, win 8192" 2017-04-28 10:13:15 id=20085 trace_id=137 func=vf_ip_route_input_common line=2586 msg="find a route: flag=04000000 gw-192.168.201.3 via Guest WiFi" 2017-04-28 10:13:15 id=20085 trace_id=137 func=fw_forward_dirty_handler line=324 msg="no session matched"This is from my FortiWIFI. 192.168.201.3 is my iphone. Does this state it can't route back from my mailserver to my vlan?
For a quick test, try enabling NAT on that policy.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
I 've done NAT and NO NAT previously. That has no affect
By some chance, are the two subnets (WiFi and internal) in the same subnet range?
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
No. the WIFI is it's own VLAN
They are both on WAN2, though, but I don;t think that should matter.
Since I see no email traffic, I am leaning that my hairpin is still wrong somehow.
dan231 wrote:No. the WIFI is it's own VLAN
They are both on WAN2, though, but I don;t think that should matter.
Are you using WAN2 as a trunk port? Can you traceroute from the WiFi to see the traffic path?
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Not sure on truck port meaning
Traceroute is one hop, since the outgoing ip is the mailserver IP.
So it recognizes that my mail server is ABC, so it doesn't look any farther in the Internet for more info.Which would mean it dies right here. Would I need something to route the traffic to the VIP then?
Which should be my hairpin policy, yes?
Should my hairpin be on the FortiWIFI then?
YES!!!
I've got it! I added the hairpin at the FortiWIFI and BOOM! Works.
Thank you all as I would never have gotten this far without your suggestions/guidance.
dan231 wrote:This is the only place your hairpin should have been. This is the gatekeeper between the Internet and your LAN. Glad you're up and running.Should my hairpin be on the FortiWIFI then?
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
I would agree..but then here we are... LOL
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.