Hello all,
Basicly I installed Forticlient-VM and Windows Server 2022 on Hyper-V.
Everything seems to work Ok except port forward.
This is how I set up th VIP
Interface = any (also tried WAN)
Type = Static NAT
External IP address/range = WAN 192.168.1.253 (Also tried 0.0.0.0)
Map to IPv4 address/range = Server ip 192.168.5.10 - LAN network
Port Forwarding = ON
Protocol = TCP
Port Mapping Type = One to one
External service port = 3389
Map to IPv4 port = 3389
I have also created firewall policy
Can any help me with any kind of a solut
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @Nuur,
This look like FortiGate is behind a NAT device. You said you are connecting from outside, what is the IP you use for connection? Is it a public IP from ISP?
Hi @mle2802
I am Connecting from the ISP Public Ip
Hi @Nuur,
From ISP router, is there port forwarding rule from ISP public IP on port 3389 to 192.168.1.253?
Hi @Nuur,
Because you are behind a NAT device so traffic cannot route to FortiGate for the VIP. ISP router must be forward traffic to FortiGate and then VIP will be kick in.
Hi @mle2802 ,
This is how i configured my isp router
The originating ip is the one I am using to reach the rdp.
Which is my hotspot connected
But it doesnt seem to work
Hi @Nuur,
Can you initiate the rdp and run the following command on fortigate and see if VIP is kick in correctly. Also make sure to bind wan interface to your VIP:
diag debug reset
diag debug flow filter addr 192.168.1.253
diag debug flow filter port 3389
diag debug flow show ip en
diag debug flow show func en
diag debug console time ena
diag debug ena
diag debug flow trace start 999
Unfortunatley the command only reacts when I rdp the server from WAN 192.168.1. or LAN 192.168.5.
If I do it from different network no reaction from the diag commands.
Is there anything I should configure in the static routing or something else?
Hi @Nuur,
If you run the command and did not get any debug when RDP from outside of the network mean that your port forwarding from ISP router is not working, we did not receive any traffic from them so I would suggest to troubleshoot with them.
Hi @Nuur,
Please collect information requested by msanjaypadma. We need those information to resolve this issue.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.