Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Port forwarding with dual Wan

Hello, I' ve run into another problem with our Fortigate 60b (FortiOS 3.0 MR7). We have two internet connections from different ISP' s in our office. These are connected to WAN1 and WAN2. Now we want to forward the HTTPS port (443) to two different IP' s in our LAN using one WAN interface for each PC in the LAN. Here is an example which should better describe the problem: WAN1_IP:443 -> WAN1 -> PC1 WAN2_IP:443 -> WAN2 -> PC2 Whenever I try to solve it with VIP' s, I get the error message: " Duplicated entry found" . Can someone help me to solve that problem? Or is that impossible? With best regards.
7 REPLIES 7
rwpatterson
Valued Contributor III

Sounds like it should work... They are different. Do you have any other VIPs terminating at either of those 2 units without port forwarding? This will stop it from working. Once you forward an entire IP, you can no longer break out ports to that same IP. You have to create groups of VIP port forwards (and group them together maybe) to do the same job thereafter. Hope this helps

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

No, I use VIP' s only to forward ports. Here is how it looks in the overview, perhaps it will help a bit: 1. VIP:
rule1 wan1(Internet)/0.0.0.0 443/tcp xxx.xxx.xxx.xxx 443/tcp
2. VIP (how it should look like):
rule2 wan2(arcor)/0.0.0.0 443/tcp xxx.xxx.xxx.yyy 443/tcp 
UkWizard
New Contributor

i have seen this before, i think its a bug with the GUI somewhere. Think i was creating address entries though. Cannot remember exactly what the cause was, sure it was zone related, or the length of a zone name. something odd like that. sorry i cannot remember exactly. Do you use zones?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
rwpatterson
Valued Contributor III

Show us the output of:
> show firewall vip

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

i' m not sure what you mean with zones, but i think we don' t use something like that... if i put in put in an external adress in one of these 2 than it works... but both should be accessible from any external ip..
rwpatterson
Valued Contributor III

There' s the deal. Port 443 can only go to an inside device once. You cannot VIP point port 443 from both outside interfaces (as far as I can tell, without some hairy trickery).

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

really? i thought because the external IP' s from the two WAN interfaces are different, it would be no problem to forward the same port to two different internal clients... we really need that for our setup here..
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors