Hi Guys,
The local Fortinet guys here seem stumped on this but let me explain.
I have a site that uses a Fortigate firewall - standard NAT configuration.
The customer has 2 core switches connected with multiple Vlans. Currently the fortigate is configured with all of the default routes of each vlan back to the core switch and the Core switch's default route out is the firewall.
Now, we have a full virtual environment on here - and we have about 24 virtual machines. part of these VM hosts are two system load balancers which would receive all the traffic from two external IP's and then route them to the specific virtual server farm. Now the problem is how can we get the source IP's to be passed to these load balancers - based on the source IP the load balancers might forward the traffic to another data center.
Remember all these servers are virtual in a sphere - Originally i thought we would need to run 3x vdom - 1 for NAtting mode for all the other servers and two in transparent mode, but im not sure how to inter-route the traffic to these VMs as the VMs would need the public IPs then. The fortigate guys here said we should use the load balance feature on the firewalls but this isnt an option as the customer needs specific information generated by their load balancers. Any ideas how to do this ??
I guess you are doing Destination NAT to your load balances(VIP)?
Then the source should not change, the LBs should see the original source.
We need to see the source IP from the client machines coming from the public interfaces -
Currently they Interface is just NAtting the external IP to the internal LB interface but we only see the firewall IP due to the natting
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.