Hi Experts,
I have configured a virtual service on Fortigate in same IP range as of outside interface. Now I have a requirement to access the Virtual server IP from same subnet servers as of backend server on virtual server.
Is this possible, if so how can I achieve this.
I am aware of hairpin NAT in case of VIP but this is a different scenario where I want to access virtual server IP. Please help
Suppose that internal subnet is 10.0.0.0/24, back-end server is 10.0.0.1 and VIP is 172.16.0.1.
I think the hosts from same subnet as back-end server will fall in some L3 related issue:
- Some host 10.0.0.2 tries to reach 172.16.0.1
- Packet reaches 10.0.0.1 through the VIP
- 10.0.0.1 replies to 10.0.0.2
- since it is on the same subnet, 10.0.0.2 receives reply directly from 10.0.0.1, not from 172.16.0.1
- Result : 10.0.0.2 drops the packet since it is unsolicited connection
So I thinks the only way for hosts from 10.0.0.0/24 to access 10.0.0.1 is to not use the VIP.
User | Count |
---|---|
2243 | |
1220 | |
771 | |
451 | |
366 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.