Solved! Go to Solution.
Yes, the Cookbook is an excellent source of information for the most common scenarios with your Fortigate. This specific recipe deals with port-forwarding VIP. As a first step, use a non-port forwarding VIP (just a plain one) to see that it works. Then add one VIP per port translation.
Please post the VIP definition and the custom service def for your port 23560 config.
You can have only 1 non-portforwarding VIP for one external address but multiple if you port-forward.
If you create multiple VIPs to reach multiple internal servers or one server via multiple services then you may create a VIP group and use this as the 'destination address' in the policy. It's a bit cleaner.
One caveat is that you will lose the ability to reach the server via a PING. ICMP will no longer work with port forwarding enabled.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
No problem for me :) Everything is now working
thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.