Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

PPTP and SMTP Passthru Requirements

Hi All, Just a beginner in Fortigate firewall. I need to do a port forwarding to an inside Windows server based PPTP server. So I believe all I need to do is to forward anything coming from internet side from any address destined to the WAN interface public IP port PPTP ( TCP 1723) and GRE ( Ip Protocol 47) over to the inside private address of this server. When I look at the manuals and knowledgebase articals, this subject has been made very confusing. Why do I need to set up any user / user groups and authentication to LDAP / Radius etc? I believe that may be the case if we also need firewall to authenticate before such users are allowed to establish session to the inside PPTP server, where they are anyway authenticated via active directory. Further the same server also hosts emails ( MS SBS). So I will do the SMTP ( tcp 25) port forwarding from same Public IP of the wwan interface to this inside server. Please advise.
13 REPLIES 13
Not applicable

Can someone comment on this please? I need to work on firewall on Monday and was looking for confirmation that I do not need to set up any pptp range and usregroup etc for the case when pptp server is Microsoft SBS. Thanks
Not applicable

Having no access to firewall yet, I am just looking into the manuals / knowledgebase articals, while doing port forwarding from external interface WAN1 ( public IP), to the inside Windows SBS server private address, I can select Port forwarding, TCP and specify 1723, where do I specify IP protocol 47 or GRE from WAN1 to SBS? Also I assume, that there is no limitation for specifying multiple ports from WAN1 to the same inside machine ( SBS in this case) as the same machine will also be used for SMTP port 25 for Email server. Thanks
Not applicable

Hello folks, Can someone help please? Thanks
RichardH
New Contributor

Create a Virtual IP and port forward 1723, then create a firewall rule wan :all -> any : virtual IP Select PPTP service (predefined with all required protocols) ACCEPT I don' t NAT this firewall rule...
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
Not applicable

Thanks RichardH. But how do I port forward for GRE ip/47?
jmac
New Contributor

You don' t need to select GRE. If you select PPTP as the service, the Fortigate includes TCP/1723 and GRE automatically.
Not applicable

Appreciate jmac. I get it now.
Not applicable

Finally what about users / user groups in this case? I do not think for passthru to Windows server that will do user authentication, we need this as indicated in manuals and KB.
RichardH
New Contributor

If you forward PPTP to the windows server, the firewalls job is done. How your internal server is configured it out of scope for this site. Edit: You may be a bit confused with PPTP to the firewall as opposed to PPTP pass-through to an internal server. Don' t mix the two, FortiOS can support a PPTP server that uses the firewall as an endpoint and requires you to create users/groups. Ignore it, you don' t need it.
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors