Created on ‎07-11-2006 03:01 AM
I am trying to forward 2 ports (port 80 and 8088) to my webserver sitting on my inside network. The funny thing is only port 80 works and not 8088.You might consider setting up the virtual IP to not limit itself to specific ports. Just forward everything, and then set the policy to forward only those two ports. Make a new service (Firewall > Service) for port 8088 and then make a group (Firewall > Service > Group) for it and HTTP and specify this group as the service in the policy. I don' t know if it would work any better, but it should take no time to try...
ORIGINAL: UkWizard On the incoming policies you would need two seperate policies, one for each VIP.I' m not sure I follow, UkWizard, why I' d need two policies, or even two VIPs. I' d just set up one VIP, to forward incoming traffic from 10.0.0.130 to 172.17.17.1, and then have a single external to internal policy to allow this, but limited to ports 80 and 8088. I wouldn' t use the VIP to restrict the traffic to specific port(s). Instead I' d use the policy for that. Granted I' m no expert, but this seems both logical, and simpler. Of course I may be missing something simple which invalidates my logic. It wouldn' t be the first time. :)
hope that makes sense.Complete sense, and thanks for your elaboration. It always amazes me that there are so many way to do things. The more I think about it, the less and less graceful my idea becomes. Two VIPs and two policies also allows for more flexibility. I hope the original poster chimes in because looking at his message (besides the port typos), it looks like his logic is sound. He does mention firewall policies (plural) for external to internal. If each specifies one VIP, it ought to be working.
Created on ‎07-11-2006 05:47 PM
User | Count |
---|---|
2635 | |
1400 | |
810 | |
677 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.