Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CHR57
New Contributor III

VIP to virtual server

I have a problem getting a WAN connection through VIP to a virtual server (with Roundrobin).

The virtual server works internally.

If I point the VIP to one of the servers in the Virtual server it works.

The policy for the Virtual server also includes the wan interface as the source.

 

Could it be a flow/proxy base thing?

 

CR
CR
1 Solution
Debbie_FTNT

Hey CR, perhaps I expressed myself a bit badly.

I essentially meant this setup:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-up-a-VIP-load-balance-with-HTTP-ho...

Can you try the VIP configuration via CLI and if the object allows itself to be configured, create a policy with that object as destination?

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++

View solution in original post

7 REPLIES 7
abarushka
Staff
Staff

Hello,

 

"Set the Inspection Mode to Proxy-based. The new virtual server will not be available if the inspection mode is Flow-based."

 

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/713497/virtual-server

 

FortiGate
CHR57
New Contributor III

Hi, it is in proxy already.

 

CHR57_0-1700207878368.png

 

CR
CR
Debbie_FTNT

Dear CR,

just to clarify:

- you already have a working setup with a virtual server object in FortiGate set up for internal users

- you are trying to set up a VIP from external to internal, and destination should be the virtual server object?

- this fails, but if you point the VIP to any of the servers BEHIND the virtual server object, access works?

 

If I understand your intended setup correctly, then the issue is probably that you're essentially trying to chain two VIPs; virtual server objects are also treated largely as VIPs in FortiGate, and it may not like that.

Can you try the following instead?
- a new virtual server object
- the VIP's external IP as virtual IP in the server object
- the same target servers as your internal virtual server object
- policy from external to internal, with new virtual server object

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
CHR57
New Contributor III

Your assumptions are correct.

 

- the VIP's external IP as virtual IP in the server object

So the Virtual server IP is the VIP external IP? Sounds strange and I can't find the SD-WAN interface in the list.
vip.jpg

"The virtual IP is overlapped with another VIP entry..."

CR
CR
Debbie_FTNT

Hey CR, perhaps I expressed myself a bit badly.

I essentially meant this setup:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-up-a-VIP-load-balance-with-HTTP-ho...

Can you try the VIP configuration via CLI and if the object allows itself to be configured, create a policy with that object as destination?

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
CHR57
New Contributor III

Think I got it, checked on my FGT at home. Will try at work on Monday.

 

Skärmbild 2023-11-17 205510.jpg

CR
CR
CHR57
New Contributor III

Worked!

Thanks.

A bit confusing to have VIPs on both Virtual IPs and Virtual Servers.

CR
CR
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors