Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
eneko
New Contributor

WAN2 - LAN Policy

Good Afternoon,

I have a 110C forti with two internet connections (WAN1 distance 10 priority 0 WAN2 distance 11 priority 0) all the traffic in WAN1 is correct.

 

I have generated a static routing policy for a particular server through the WAN2 and a policy to allow access to internet (LAN - WAN2) and works OK.

 

The problem comes when I expose a web on that server, i can´t access from Internet (from lan internally entered correctly), I have generated policy WAN2 - LAN and does not work (that policy works correctly, i prioritized WAN2 on WAN1 and the access is ok).

 

Many thanks for your attention.

13 REPLIES 13
tuumke
New Contributor

Is NAT enabled in the policy?

eneko
New Contributor

hi tuumke,

 

Yes, I try removing it and nothing happens...

rwpatterson
Valued Contributor III

Make the distances the same, and change the priorities. Higher number=lower priority.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
tuumke
New Contributor

Okai,

 

So you need a port forward on the fortigate.

http://docs-legacy.fortinet.com/cb/html/index.html#page/FOS_Cookbook/Firewall/cb-firewall-dnat3.html

 

1. Go to Firewall Objects > Virtual IP > Virtual IP and select Create New to add a virtual IP that maps connections to the wan2

Name TCP80-Webserver

External Interface wan2 Type Static NAT External IP Address/Range 0.0.0.0-0.0.0.0 (i think) Mapped IP Address/Range ip webserver - ip webserver

 

 

2. Select Port Forwarding and configure the following port forwarding settings:

Protocol TCP External Service Port 80-80 Map to Port 80-80

 

Repeat for TCP443

 

4. Go to Firewall Objects > Virtual IP > VIP Group and select Create New to add a VIP Group that includes both VIPs.

Group Name TCP80-443-Webserver Interface wan2

Add both created vips (TCP80 and TCP443) to the members list

 

5. Go to Policy > Policy > Policy and select Create New to add a policy that accepts includes the VIP Group.

 

Source Interface/Zone wan2 Source Address all Destination Interface/Zone internal Destination Address TCP80-443-Webserver Schedule always Service HTTP and HTTPS Action ACCEPT

 

(edited because tables didnt work for some reason lol)

eneko
New Contributor

Good morning,

 

The policy is created as you say, take a look.

 

Test (destination address) is a virtual ip configure correctly, if i priorize wan2 on wan1 it works well but if wan1 is priorize on wan2 doesn´t work.

 

Trank you very much!

tuumke
New Contributor

eneko wrote:

Good morning,

 

The policy is created as you say, take a look.

 

Test (destination address) is a virtual ip configure correctly, if i priorize wan2 on wan1 it works well but if wan1 is priorize on wan2 doesn´t work.

 

Trank you very much!

And you also created the VIPs? (that is the test group i assume?) Screenshot? :)

eneko
New Contributor

yes

tuumke
New Contributor

eneko wrote:

yes

And i assume you still have the problem?

Can you give screenshots of the created VIPs?

 

eneko
New Contributor

Hello tuumke,

 

we continue with the problem, i attached virtual ip capture

Labels
Top Kudoed Authors