I am helping someone implement an on premise Lync solution for SIP; they currently utilize O365 for everything else (i.e. email, voicemail, etc.). Their setup consists of a front end server, edge server, and reverse proxy server. Can someone please offer guidance on how to make this work with a FortiGate 100D running FortiOS 5.2? Hopefully I have provided enough details below; subnets are fake and for illustration purposes only.
Current Setup They have a dedicated Internet connection that bypasses their Fortinet firewall completely. The external interfaces of the edge and reverse proxy servers are DIRECTLY bound to this spare connection.
Desired Setup Move the spare Internet connection to port WAN2 on the Fortinet. Utilize the DMZ on the Fortinet for external interfaces of the edge and reverse proxy servers. Single consolidated edge with private IP addresses and NAT in Lync Server 2013 (https://technet.microsoft...ibrary/gg399001.aspx).
Fortinet Interfaces WAN1 – 20.20.20.16/29 WAN2 – 30.30.30.16/29 DMZ – 10.10.2.1/24 LAN – 192.168.0.2/24
Layer 3 Switch DATA (VLAN 10) – 192.168.0.1/24 VOICE (VLAN 100) – 192.168.100.1/24
Lync Servers Front End 192.168.0.60
Edge Internal 192.168.0.62 External SIP Access: 10.10.2.4 -- 30.30.30.19 (1:1 NAT) Web Conferencing: 10.10.2.5 -- 30.30.30.20 (1:1 NAT) Audio Video: 10.10.2.6 -- 30.30.30.21 (1:1 NAT)
Reverse Proxy Internal 192.168.0.61 External 10.10.2.7 -- 30.30.30.22 (1:1 NAT)
Fortinet Configuration Created Virtual IP's for each 1:1 NAT. Created IP Pool's for each 1:1 NAT. This ensures that traffic going out 10.10.2.4 is seen as 30.30.30.19, 10.10.2.5 is seen as 30.30.30.20, etc. Created second static route pointing to WAN2 with a priority of 10. Created a policy route to force all traffic from DMZ to WAN2. Created the necessary security policies to pass traffic between the DMZ and WAN2.
Disabled SIP helper and disabled rtp on the VOIP profile.
Outcome All services appear to be working with the exception of the ability to check voicemail internally. When calling voicemail it will ring at least once and then the call goes dead (eventually followed by a fast busy signal).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.