Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
etep
New Contributor

Port forwarding troubles from WAN to LAN

Hello,

New fortigate-40f user (v7.2.10 build1706 (Mature)) here trying to struggle a port forward from WAN to LAN web server.

I checked the guides for virtual ip & firewall policy, but for some reason the internal ip/ service stays unreachable.The rules i created are.

1. virtual ip

1.jpg

2.firewall policy(tested with nat enabled & disabled with same result)

2.jpg

 

 

Any idea what is the issue here?

 

yours

Etep

 

8 REPLIES 8
dingjerry_FTNT

Hi @etep ,

 

Please specify the External IP in the Virtual IP settings.

Regards,

Jerry
etep

Hello,

 

tested with the "wan ip", but it didn't work

3.jpg

 

also tested with "physical interface" address, but that didnt work either.

What does this "physical interface ip" mean?

4.jpg

Yours

Etep

dingjerry_FTNT

Hi @etep ,

 

That is the real IP assigned to the WAN interface.  What is the IP 109.204.176.115? I don't think that this is an IP assigned to the WAN interface.

 

Please specify the external IP with 100.64.28.202 for a try.

Regards,

Jerry
etep

Hello,
the IP 109.204.176.115 seems to be the IP that the devise was assigned

5.jpg

 

however tested now with the 100.64.28.202 IP, but service is still unreachable.
6.jpg

 

 

Yours

Etep

funkylicious

hi,

if you dont have a public ip directly assigned to you, maybe your ISP does the NAT on another device, in which case they should do a DNAT on that also.

"jack of all trades, master of none"
"jack of all trades, master of none"
dingjerry_FTNT

Hi @etep ,

 

Apparently, the 109 IP is not the one assigned to your WAN interface.  It is a public IP from your ISP.  The real IP for your WAN interface is the 100.64.x.x IP.

 

There must be an ISP modem and I don't think you can access it.  If you do, please make sure that you configure port forwarding on that modem.  Otherwise, please ask your ISP to help you.

 

That means, that when someone from the Internet accesses the 109 IP, the ISP modem needs to know to forward the traffic to the 100.64 IP.

 

And you need to specify the 100.64 IP as the external IP in the virtual IP settings.

Regards,

Jerry
Toshi_Esumi

100.64.0.0-100.127.255.255 range is used for CG-NAT by your ISP.
https://www.draytek.co.uk/information/blog/what-is-cgnat
Which is not reachable from the internet. The real IP, which is 109.204.176.115, is shared with ISP's other customers. Therefore, there is no way to reach your 40F's wan interface from the Internet.

 

If you have to host a web server/services, you need to either look for another ISP, which doesn't do CGNAT, or get a static IP service from the current ISP, which might require a business account/service with additional onetime+MRC(monthly recurrent change).

Toshi

etep
New Contributor

Hello everyone,

 

BIG thank you for everyone explaining and making me realize that i had an "natted" ip. Got confused with the new gui etc. since my old apparatus was Zyxell.
Anyways i contacted my ISP and got me an public ip address. Now the Virtualip (with my preference 0.0.0.0 as external ip since i have a client on lan which yells the ip to dns provider) & Firewall policy works as intended.

1.jpg2.jpg

 

Kudos to everyone helping a noob on this matter #heart

 

Yours

Etep

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors