- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Virtual IP setup
Hello!
I am setting up a service that will live behind the Fortigate Firewall and I have the Virtual IP setup. I have inbound and outbound rules setup that should allow traffic, however when I try to ping or anything else to the virtual IP I don't get any response. Because the Public IP will only be used for the service I don't have NAT setup. This firewall also is only connected to one line out to our ISP who also has us a block of IP addresses. Here is the rule:
Incoming Interface: Virtual Wan Link
Outgoing: Internal Service
Source: All
Destination: VIP
Schedule: Always
Service All
NAT disabled.
Other rule:
Incoming Interface: Internal Service
Outgoing: Virtual Wan Link
Source: all
Destination: all
Schedule: always
Service: All
NAT Disabled
Is there anything I am missing?
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @BrettJ.,
Please refer to this article to collect debug flow to see if the traffic is being dropped or not: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Those are policies for two different sessions: incoming sessions and outgoing sessions. The outgoing sessions are like for when you access a web site on the internet from your server's browser. Not for the returning packets for the VIP access from outside. So for that direction you still need NAT/SNAT enabled.
Then your VIP config is questionable if you forwarded all ports/protocols to the server and couldn't get ping responses. Please share us the VIP config.
Then you need to run sniffing and flow debugging to troubleshoot.
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @BrettJ.,
Please refer to this article to collect debug flow to see if the traffic is being dropped or not: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Regards,
