Running v5.6.2, created a VIP under DNAT & Virtual IP's with a port forward.
Create a new policy and when select destination, the VIP isn't listed, only addresses. I made for interface setting in VIP and poicy are the same for incoming. Anyone seen this? I've made VIP's in 5.4/5.2 the same way and worked fine....
Thx
Dave
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Guys,
Please note that when Central SNAT is enabled not only Source NAT is handled by central table but also Destination NAT also handled by a central table...
What you have to do is, once Central SNAT is enabled, just create DNAT/Virtual IP mapping and then create security policy with destination address of the actual server IP, not the VIP.
If you did port forwarding you may need it tied to a specific port (if you left the external ip as 0.0.0.0). Did you leave it as "any" when creating the VIP?
Mike Pruett
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.