Created on ‎06-21-2004 09:46 PM
I am using the EXACT same configuration as I had working with a Netscreen unit (don' t get me wrong, I like Fortinet a LOT better). Why doesn' t the traffic get routed out on the correct IP... why does it use the Fortinet box internal IP?
------------------------------------
Sorry for the long winded post, I didn' t want to leave out any details and would really appreciate any thoughts people could give this.
Thanks so much,
Chris
The critical point here is that when packets go internal -> external through the Fortinet and find a matching VIP, it shouldn' t just re-route back internally and wipe out the source IP, changing it to 192.168.1.1
18.663621 192.168.1.1.53923 -> 192.168.1.12.53: udp 122
0x0000 0004 0001 0006 0009 0f30 08cd 0001 0800 .........0......
0x0010 4500 0096 e4ee 0000 7f11 d30a c0a8 0101 E...............
0x0020 c0a8 010c d2a3 0035 0082 a22c 0000 2400 .......5...,..$.
0x0030 0001 0001 0000 0000 0d73 6f6d 656e 6577 .........somenew
0x0040 646f 6d61 696e 036f 7267 0000 0600 01c0 domain.org......
0x0050 0c00 0600 0100 000e 1000 4b03 6e73 310f ..........K.ns1.
0x0060 0000 0000 0000 0000 0000 7374 696e 6703 XXXXXXXXXXX.
0x0070 636f 6d00 0a68 6f73 746d 6173 7465 720d com..hostmaster.
0x0080 736f 6d65 6e65 7764 6f6d 6169 6e03 6f72 somenewdomain.or
0x0090 6700 7773 8ffa 0000 0e10 0000 0384 0009 g.ws............
0x00a0 3a80 0000 3840 :...8@
| User | Count |
|---|---|
| 2787 | |
| 1423 | |
| 812 | |
| 747 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.