Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sepehradmin
New Contributor

Problem NAT With Multiple External IP

Hi all, First of all, I explain my situation to better understand the subject. I have a several servers behind Fortigate Firewall with 14 valid IP addresses that to each server assigned one valid IP. Those IP addresses mapped to servers with VIP. assume that WAN interface IP address of firewall is 56.20.20.18 and valid IP address of my servers started from 56.20.20.19 to 56.20.20.25 . now from the internet, when i enter my web server valid IP (56.20.20.22) into the browser, the returned valid IP was 56.20.20.18 (WAN interface of Firewall). The problem is that instead of showing valid IP of web server, The valid IP address of WAN interface of Firewall shown in Client PC. I know about IP pool and Dynamic NAT. but i want each server has static valid IP address and after calling them from internet, the real valid IP of them shows into the web browser. therefore dynamic NAT not working in this case. Please direct me to the right place and show me how create suggestion rule(s). thanks in advanced.
1 REPLY 1
Christopher_McMullan

Could you show the details for your VIP and firewall policy, and your WAN interface? Please also try running some diagnostics: sh sys int wan1 //--as one example; use your WAN-facing port sh firewall vip vip_name sh firewall policy x //--integer of policy utilizing the VIP diag debug reset diag debug enable diag debug flow show console enable diag debug flow show function-name enable diag debug flow filter addr w.x.y.z //--public IP of test client connecting to the VIP from the outside diag debug flow trace start 5000 <try to access the server, then...> diag debug flow trace stop diag debug flow filter clear diag debug reset diag debug disable You can post the output here. If the solution is obvious, or other members can work on it, you may have your answer. Otherwise, you can open a ticket armed with these debugs and a copy of your configuration file.

Regards, Chris McMullan Fortinet Ottawa

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors