Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BrettJ
New Contributor

Virtual IP setup

Hello!

 

I am setting up a service that will live behind the Fortigate Firewall and I have the Virtual IP setup. I have inbound and outbound rules setup that should allow traffic, however when I try to ping or anything else to the virtual IP I don't get any response. Because the Public IP will only be used for the service I don't have NAT setup. This firewall also is only connected to one line out to our ISP who also has us a block of IP addresses. Here is the rule:

Incoming Interface: Virtual Wan Link

Outgoing: Internal Service

Source: All

Destination: VIP

Schedule: Always

Service All

NAT disabled.

 

Other rule:

Incoming Interface: Internal Service

Outgoing: Virtual Wan Link

Source: all

Destination: all

Schedule: always

Service: All

NAT Disabled

 

Is there anything I am missing?

1 Solution
hbac
Staff
Staff

Hi @BrettJ.,

 

Please refer to this article to collect debug flow to see if the traffic is being dropped or not: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...

 

Regards, 

View solution in original post

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

Those are policies for two different sessions: incoming sessions and outgoing sessions. The outgoing sessions are like for when you access a web site on the internet from your server's browser. Not for the returning packets for the VIP access from outside. So for that direction you still need NAT/SNAT enabled.

 

Then your VIP config is questionable if you forwarded all ports/protocols to the server and couldn't get ping responses. Please share us the VIP config.
Then you need to run sniffing and flow debugging to troubleshoot.

 

Toshi

hbac
Staff
Staff

Hi @BrettJ.,

 

Please refer to this article to collect debug flow to see if the traffic is being dropped or not: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...

 

Regards, 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors