Hi Experts,
I have configured a virtual service on Fortigate in same IP range as of outside interface. Now I have a requirement to access the Virtual server IP from same subnet servers as of backend server on virtual server.
Is this possible, if so how can I achieve this.
I am aware of hairpin NAT in case of VIP but this is a different scenario where I want to access virtual server IP. Please help
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Suppose that internal subnet is 10.0.0.0/24, back-end server is 10.0.0.1 and VIP is 172.16.0.1.
I think the hosts from same subnet as back-end server will fall in some L3 related issue:
- Some host 10.0.0.2 tries to reach 172.16.0.1
- Packet reaches 10.0.0.1 through the VIP
- 10.0.0.1 replies to 10.0.0.2
- since it is on the same subnet, 10.0.0.2 receives reply directly from 10.0.0.1, not from 172.16.0.1
- Result : 10.0.0.2 drops the packet since it is unsolicited connection
So I thinks the only way for hosts from 10.0.0.0/24 to access 10.0.0.1 is to not use the VIP.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.