 
					
				
			
			
				
			
			
				
			
			
			
			
			
			
		And I had no success. www.whatsmyip.net shows x.x.x.126 intead x.x.x.122. Pinging x.x.x.122 I don' t receive a response.This is a port-forward VIP so only those services are pinhole to the inside. You need to enable NAT on a policy that allows the inside server outbound for all other traffic if required. It would used the .126 WAN interface or build a ip nat-pool and select that pool for the traffic originating from the inside outbound. All traffic that maps the VIP will automatically reply with the vip mapped-ip. Also diag debug flow with filters would help you understand what fwpolicies are used for both the in or out. Do a search here with the above 3 words, for many examples. BTW, your diagram was extremely helpful. I wish more will explain what they are doing via diagrams. This will assist us with give you guidance or direction.
 Start with one VIP 1st and then build the group later so you get comfortable on the operation, but your on the right track.
 
 Start with one VIP 1st and then build the group later so you get comfortable on the operation, but your on the right track.
					
				
			
			
				PCNSE
NSE
StrongSwan
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.