Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

PPTP and SMTP Passthru Requirements

Hi All, Just a beginner in Fortigate firewall. I need to do a port forwarding to an inside Windows server based PPTP server. So I believe all I need to do is to forward anything coming from internet side from any address destined to the WAN interface public IP port PPTP ( TCP 1723) and GRE ( Ip Protocol 47) over to the inside private address of this server. When I look at the manuals and knowledgebase articals, this subject has been made very confusing. Why do I need to set up any user / user groups and authentication to LDAP / Radius etc? I believe that may be the case if we also need firewall to authenticate before such users are allowed to establish session to the inside PPTP server, where they are anyway authenticated via active directory. Further the same server also hosts emails ( MS SBS). So I will do the SMTP ( tcp 25) port forwarding from same Public IP of the wwan interface to this inside server. Please advise.
13 REPLIES 13
RichardH
New Contributor

For SMTP you can play with multiple protocols on the firewall rule adding the SMTP service. (For this to work, you should remove 1723 on the port forward portion of the virtual IP setup)
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
Not applicable

Hi RichardH, Of course my fundamentals are very clear and I know the difference between PPTP termination on the firewall or PPTP passthru to the internal server. And I am not asking about anything to do with configuration of internal server. If you will review any documentation from Fortinet on PPTP passthru, they always talk about creating users / user groups on the firewall even though it should be none of business of firewall, other than opening ports for PPTP and GRE. So that is the confusion. When I do Cisco firewalls, I simply have to open up PPTP and GRE thru the firewall and a static (VIP) for the inside server. I hope this time I am more clear as to my question. Thanks
RichardH
New Contributor

Ignore the language, just do a pass-through and it' ll work.
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
Not applicable

Excellent. Really appreciate all your help.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors