- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unable to reach virtual server on a VLAN
Hi,
I've created virtual servers on Fortigate (eg: mail.customer.com, phone.customer.com...) and all works on LAN, but when i connect my pc to a VLAN i can't reach no one of them, so if (for example) i want to connect to my mail server it didn't works.
I'm able to ping mail.customer.com (return public IP).
I've created firewall policy rule but i'm not sure how to create static route and/or policy route.
Can you help me?
Thanks.
- Labels:
-
VLAN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Need way more details here. Does DNS work? Is there a policy in place? Is this inbound NAT using a virtual IP? Something else?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've reply with my configuration
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @roberto_papa ,
Could you please attach the FGT config?
Or at least share the VIP configurations and relevant firewall policies.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've reply with my configuration
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @roberto_papa
With this limited information, it would be difficult to provide or suggest next action plans.
regards,
Sheikh
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If i ping a virtual server it return me public IP, not local IP (i don't want to forward traffic locally VLAN-LAN).
I've created virtual server for VLAN:
and policy
I don't create DNS server for VLAN because i want ping virtual server by public IP, not local IP (if create DNS server for VLAN is the only possible solution, i create it).
Tracert goes out, but it stop on public IP when the packet return.
Maybe it's a static routes problem:
or policy route problem:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1) I am not sure why you are not using VIP. You are using Virtual Server unless you have multiple real servers for load balancing; otherwise, you may use VIP. Apparently, you don't.
Please check this KB for how to configure VIP:
2) The static route for the external IP of your Virtual Server is supposed to be linked to "VLAN Ospiti", not "lan".
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Oh, the policy route is not necessary.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have multiple virtual server that use same source port, so i can't use VIP but virtual server.
