Hello!
I am setting up a service that will live behind the Fortigate Firewall and I have the Virtual IP setup. I have inbound and outbound rules setup that should allow traffic, however when I try to ping or anything else to the virtual IP I don't get any response. Because the Public IP will only be used for the service I don't have NAT setup. This firewall also is only connected to one line out to our ISP who also has us a block of IP addresses. Here is the rule:
Incoming Interface: Virtual Wan Link
Outgoing: Internal Service
Source: All
Destination: VIP
Schedule: Always
Service All
NAT disabled.
Other rule:
Incoming Interface: Internal Service
Outgoing: Virtual Wan Link
Source: all
Destination: all
Schedule: always
Service: All
NAT Disabled
Is there anything I am missing?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @BrettJ.,
Please refer to this article to collect debug flow to see if the traffic is being dropped or not: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Regards,
Those are policies for two different sessions: incoming sessions and outgoing sessions. The outgoing sessions are like for when you access a web site on the internet from your server's browser. Not for the returning packets for the VIP access from outside. So for that direction you still need NAT/SNAT enabled.
Then your VIP config is questionable if you forwarded all ports/protocols to the server and couldn't get ping responses. Please share us the VIP config.
Then you need to run sniffing and flow debugging to troubleshoot.
Toshi
Hi @BrettJ.,
Please refer to this article to collect debug flow to see if the traffic is being dropped or not: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1517 | |
1013 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.