Hey guys,
I followed the instruction on the cookbook to configure port forwarding with an application called go global. When i am connected to my LAN, it works just fine but then when I connected to the internet on the other side of the firewall it does not work. Please, i need help on this ASAP!
hi,
please post some more infos: FortiOS version, VIP definition, policy. Preferable from the CLI/console, in text form. We'll see how I can help then.
Hello. Thanks for your response.
Virtual IP
1. External IP Address/ Range: Virtual IP address
2. Mapped IP Address/Range: Server Local IP address.
3. Port Forwarding
Protocol TCP UDP SCTP ICMP External Service Port - Map to Port - VIP Group Name Comments0/255 Interfacewan1 (WAN TO AIRTEL) MembersWebserver-goglobal Webserver-80
POLICY TO ALLOW TRAFFIC
Incoming Interfacewan1 Source Address all Source User(s)Click to add... Source Device TypeClick to add... Outgoing Interfaceport2 Destination AddressWebserver-http-vip Schedule always ServiceALL ActionACCEPT
NAT-DISABLED
AntiVirusdefault default Web Filterdefault block-security-risks default flow-monitor-all monitor-all web-filter-flow Application Controldefault block-p2p default monitor-p2p-and-media P2P Youtube-Blocking IPSdefault all_default all_default_pass default high_security protect_client protect_email_server protect_http_server Email Filterdefault default VoIPdefault default strict SSL/SSH Inspectioncertificate-inspection certificate-inspection deep-inspection
Shared Shaperguarantee-1Mbps guarantee-1Mbps high-priority low-priority medium-priority shared-1M-pipe Special Shaper Very low bandwidth Reverse Shaperguarantee-1Mbps guarantee-1Mbps high-priority low-priority medium-priority shared-1M-pipe Special Shaper Very low bandwidth Per-IP ShaperNo_bandwidth No_bandwidth
Log Allowed Traffic Security Events All Sessions Capture Packets Comments0/1023 Enable this policy Cancel
You get much better readability if you post the configuration from the CLI instead of the web interface. The above is a hot mess.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Obie,
Please clarify, are you hosting this "Go Global" application or are you just trying to connect to it?
If you are hosting it, then using a VIP, ports and creating the associated policy to allow traffic inbound will work. If this is the case, you should be able to Telnet to the port from the outside if it has been opened. Also, if there are multiple ports needed, you may need to create more than one VIP if the ports aren't in a range.
As noted above, posting the config from the CLI would be preferred.
Thanks
Sidewaysguy
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.