Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nuur
New Contributor

Port forward to RDP

Hello all,

 

Basicly I installed Forticlient-VM and Windows Server 2022 on Hyper-V.

Everything seems to work Ok except port forward.

This is how I set up th VIPSchermafbeelding 2023-09-27 215844.png

Interface = any (also tried WAN)
Type = Static NAT
External IP address/range = WAN 192.168.1.253 (Also tried 0.0.0.0)
Map to IPv4 address/range = Server ip 192.168.5.10 - LAN network
Port Forwarding = ON
Protocol = TCP
Port Mapping Type = One to one
External service port = 3389
Map to IPv4 port = 3389

I have also created firewall policy

Schermafbeelding 2023-09-27 220844.png

Can any help me with any kind of a solut

 

 

25 REPLIES 25
Nuur
New Contributor

I see no traffic when I use diag commands

dbu
Staff
Staff

Hi @Nuur ,

 

Here is how it works in my lab:

This is the VIP object we create to translate from external public IP to the internal server's IP address 


tempsnip1.png

 

Here is the firewall policy :

tempsnip2.png

 

Then RDP to the external IP address of the Fortigate configured on port 1

tempsnip3.PNG

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Nuur
New Contributor

All these settings is also wat I have

 

But are u rdping from the same network?

 

I am connecting from different network

dbu

I am connecting from different network  ( changed the External IP for this screenshot only), this is why i need the NAT enabled. 

Configuration itself is pretty basic, the only thing you need to verify is reachability of the RDP server from FGT and yours to FGT. 

Maybe you are hitting the wrong firewall policy. 
Run this commands in order to find out.  

diag debug reset

diag debug flow filter addr 192.168.100.200    >>>> replace with the targed RDP

diag debug console timestamp enable

diag debug flow show iprope enable

diag debug flow show function-name enable

diag debug enable

-Start doing RDP 

diag debug flow trace start 200

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Nuur
New Contributor

I am using a vm Fortigate.

 

Is it possible that you guys are all uising actual Foritgate?

dbu

@Nuur 
I believe it does not matter what platform you are using. 
Btw mine is VM :)

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors