Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Routing for FTP Server

Hi, I have FTP Server in my Organisation, I need FTP server to have Public IP as my vendors will directly FTP to the server and dump the files, also i need local LAN team to access that files, I have Router ethernet connecting to fortigate firewall 800 external interface and Internal Interface connecting to inside network Kindly let me know how do i achieve the same Thanks....Kiran
32 REPLIES 32
rwpatterson
Valued Contributor III

What you need to do here is to create a virtual IP (VIP). This will tell the Fortigate (FGT) what outside IP will be pointed to a private LAN address. Under Firewall > Virtual IP, create a new VIP. It' s prettyr straight forward. What you need to remember is that in the policy, use this VIP definition, not the private IP address of the FTP server. Good luck, and welcome to the forums.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

Thanks Bob, will check and update you, Cheers, Kiran
Not applicable

Hi, I had configured the VIP and policy aswell on my fortigate 800, but when i try to ftp from the outside I am unable to connect to my FTP server, Outside:202.150.105.15 is mapped to Inside:125.120.0.12 policy rule is external interface to inside destination VIP allow FTP services, Pls letme know i missed anything
rwpatterson
Valued Contributor III

What is the policy you used? Source all? Is the VIP definion open services or just a single port (port forwarding)? Are you sure the port number is correct? (FTP is 21) Did you use the built-in FTP definition or create your own?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

Policy is simple External Interface all >> inside - FTP (Destination) where FTP is VIP definition, its port forwarding for port 21 i used the builtin FTP definition, Regards,
rwpatterson
Valued Contributor III

Does the FTP server respond from inside the FGT firewall?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

FTP Server have 2 NIC card, one using the outside and other internal IP address, I am able to ping internal network to FTP server and also from FGT am able to ping both interfaces, outside and inside Regards,
rwpatterson
Valued Contributor III

As a test, open up the port forwarding on the VIP definition, and allow PING on the policy. From an Internet based PC, ping the FTP server. If this fails, run a traceroute and see how far you get. This may give you some insight as to why this whole thing is failing. It looks pretty simple to me. I cannot see why this is failing without more information. Also, what do you mean by ' outside' port on the FTP server? Is there a port connected directly to the Internet?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

on the VIP definition i have opened the Port forwarding to port 21, enabled the PING aswell, Do i need to enable NAT on the Policy ?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors