Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Syed_Mehmood_Ali
New Contributor III

Server Accessing Issue Please Help

I' m using forigate 100D with FortiOS 5. My scenario is I' m using WAN 1 (primary) for internet purpose and WAN 2 (secondary) for NATTing the servers with different static public IP addresses. My servers are NAT through WAN 2 and users are NAT through WAN 1. The problem is users can' t access the server going from WAN 1 to WAN 2 but can access locally. Also the users from outside our network can access the server. Please kindly help me to solve this issue that users going from WAN 1 access the server going from WAN 2.
8 REPLIES 8
Syed_Mehmood_Ali
New Contributor III

Ok I have resolved my issue by creating local DNS server listing on fortinet. http://docs-legacy.fortinet.com/cb/html/FOS_Cookbook/Install_advanced/dns_server_dns_database.html Thanks anyway
ede_pfau
SuperUser
SuperUser

This may be a dumb question, but: have you created a policy from WAN1 to WAN2 to allow this traffic?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Syed_Mehmood_Ali
New Contributor III

Nope I didn' t dude. Why are you asking ?
ede_pfau
SuperUser
SuperUser

Well, traffic originates from internal, leaves at WAN1 to access the VIP on WAN2 to come back in. As the traffic flows between 2 interfaces you need a policy to allow that.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Syed_Mehmood_Ali
New Contributor III

Thanks ede_pfau, I have added the policy for WAN 1 to WAN 2 and WAN 2 to Wan1 to allow traffic. I forgot to add this policy.
ede_pfau
SuperUser
SuperUser

...and does it work if you are using the " public" DNS names?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Syed_Mehmood_Ali
New Contributor III

Yup users at WAN 1 easily accessing the VIP through public dns which is on WAN 1 but VIP at WAN 2 is not accessible by WAN 1 users and also the WAN 2 users dont know why.
Syed_Mehmood_Ali
New Contributor III

My WAN 2 users are not communicating with WAN 1 VIPs but my WAN 1 users can communicate WAN 2 VIPs through public DNS names, someone tell me what I' m doing wrong.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors