Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Opening port for SQL server

I have a web server on my dmz zone and need to query to my sql server in the internal for a database content. I tried to open port 1433 for SQL (dmz-internal and interna-dmz) but the web server cant communicate to SQL server. I tried to open all the ports (without protection profile) on both ways but still the same. I am wondering is this a known issue of Fortigate for SQL and if there' s any remedy for this? By the way, If I use my other firewall (Interjak) I dont have any issue at all. I am using FG-100 with v2.8 MR5 Chris
4 REPLIES 4
UkWizard
New Contributor

do you have the fortinet as the default route on the internal boxes ? Make sure you have a rule allowing the internal machine to access the dmz machine as well.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

NO, my firewall is not my default gateway for internal zone. I have another router inside my internal which is the default gateway of the internal zone. The reason why we have a router inside the internal because of inter-office connection. The router is configured to route all the request to the internal IP address of the firewall and inside my firewall, I set a static route pointing to my internal firewall if there' s a request to internal subnets. I think my configuration is working as I can ping and connect to my dmz zone boxes and vice-versa. Only this SQL service that I am having a problem. I hope this give you more info.
UkWizard
New Contributor

Temporarily, create a rule from DMZ -> INT from webserver to sql server, and another rule from INT -> DMZ from sqlserver to web server. BOTH with NAT disabled. Ensure these two rules are also AT THE TOP of the rulebases. Then make sure that the webserver has the firewall as the default gateway ? Test pings back and forth to ensure connectivity, then test the sql. If it still doesnt work, try putting another rule at in the INT -> EXT allowing SQL to anywhere. As what could be happening is the webserver is getting natted behind the external VIP ip address. Thus the sql server may not have access to the EXT IO. Let me know how you get on.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Can you connect to that SQL server from the same internal network ? do you see any connection attempts/failures reported on the Fortigate and/or SQL server logs ?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors