To publish our websites behind our Fortigate unit, we initially used Static NAT in our Virtual IPs (VIPs) and then created the policies to publish the site and allow only HTTP and HTTPS traffic to them. We recently had occasion to make us investigate using Port Forwarding for our VIPs.
Once we changed the VIPs to be Port Forwarding, I could no longer do a tracert to the public IP of any of our websites. It would hit the LAN IP of the Fortigate and then give me " Destination Host Unreachable" . I also could not reach some of our sites internally even though an nslookup correctly identified the public IP address they were using. Without the Static NAT, it' s like the public IP addresses are not bound to the NIC of the firewall.
Has anyone else seen anything like this and, if so, how did you overcome it besides the obvious - use Static NAT?