Hi,
I've created virtual servers on Fortigate (eg: mail.customer.com, phone.customer.com...) and all works on LAN, but when i connect my pc to a VLAN i can't reach no one of them, so if (for example) i want to connect to my mail server it didn't works.
I'm able to ping mail.customer.com (return public IP).
I've created firewall policy rule but i'm not sure how to create static route and/or policy route.
Can you help me?
Thanks.
Need way more details here. Does DNS work? Is there a policy in place? Is this inbound NAT using a virtual IP? Something else?
I've reply with my configuration
Hi @roberto_papa ,
Could you please attach the FGT config?
Or at least share the VIP configurations and relevant firewall policies.
I've reply with my configuration
Hello @roberto_papa
With this limited information, it would be difficult to provide or suggest next action plans.
regards,
Sheikh
If i ping a virtual server it return me public IP, not local IP (i don't want to forward traffic locally VLAN-LAN).
I've created virtual server for VLAN:
and policy
I don't create DNS server for VLAN because i want ping virtual server by public IP, not local IP (if create DNS server for VLAN is the only possible solution, i create it).
Tracert goes out, but it stop on public IP when the packet return.
Maybe it's a static routes problem:
or policy route problem:
1) I am not sure why you are not using VIP. You are using Virtual Server unless you have multiple real servers for load balancing; otherwise, you may use VIP. Apparently, you don't.
Please check this KB for how to configure VIP:
2) The static route for the external IP of your Virtual Server is supposed to be linked to "VLAN Ospiti", not "lan".
Oh, the policy route is not necessary.
I have multiple virtual server that use same source port, so i can't use VIP but virtual server.
User | Count |
---|---|
2640 | |
1400 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.