Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pdenhaan
New Contributor

Virtual IP map to VPN IP

Hi all,

 

I don't know if it is possible but maybe you guys can help me out.

 

So we want our Exchange Online mailserver sending certain e-mails to a backend system.

Mails are send to the Fortigate virtual IP and maps it to an IP address behind a S2S vpn.

Policy:

From 'WAN'

To 'S2S'

Source: Exchange Online servers

Destination: VIP

Port: 25

 

I also added the public IP address to the Phase 2 Selector on the S2S.  There is some traffic hitting the policy but on the other end of the VPN no traffic is seen.

 

Anyone got an idea?

 

Greetings,

Paul

1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

I should work as long as the other side routes packets toward the online sever back through the tunnel. Check the routing on the other end and if correct, run sniffer on both ends while sending port 25 traffic to the wan interface. You might need to disable "auto-asic-offload" at the policies to see all packets through the tunnel in sniffing.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors