Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kevin_Noble
New Contributor

XBOX Config Instructions from Knowledge Centre

Has anybody tried setting up their Fortigate for use with an XBOX as outlined in the Fortinet Knowledge Centre. I tried it but cannot seem to get the XBOX NAT status to show anything but " strict" - it has to be " open" to be able to play XBOX live without restrictions.
6 REPLIES 6
Kevin_Noble
New Contributor

I seem to have it working now - besides what was in the instructions, I had to add an outbound rule that was setup to used a NAT with a fixed port from the XBOX static IP address to all outbound.
Oberon
New Contributor

hi Kevin can you tell me what exactly you did, to make it work? I have also an xbox at home, even I had so fare no time to use it (got it for free with a hp server :). I have strict nat configuration when I test the xbox-live connection. kr Ralph
Private Use: Fortigate-50B, 4.00-MR3, NAT/IPsec-VPN/SSL-VPN
Private Use: Fortigate-50B, 4.00-MR3, NAT/IPsec-VPN/SSL-VPN
Kevin_Noble
New Contributor

I followed the instructions in the Fortigate Knowledge Centre article ID 3568 but I also could not get it off of strict until I added a rule using NAT with a fixed port for the Internal to WAN1 above my general outgoing NAT rule. The last step in the article clued me in that this may be required since it is also required for the inbound rule. I added a name for the XBOX under the firewall address section (that used the static IP that was defined on the XBOX), and then added a rule from it on Internal to External All using NAT but I also clicked Fixed Port - it is very important that this rule be above any other general outbound NAT rules (maybe put it at the top of your rule set) and that you select " fixed port" . The fixed port outbound seemed to be what made it finally take effect and show open. I also noticed that it took a couple minutes before the test from the XBOX would show open - perhaps because there were existing sessions on the Fortigate that had to timeout before the new config would take effect. Let us know if you get it working.
Oberon
New Contributor

hi Kevin thanks for your help, yes it works now. You are right with your extra rule, I tried first without, but it still showed strict, like yours. Then I added the rule and it worked right after with the status open. now I need finally to open an account on xbox live! :) haven' t done it so fare. kr Ralph
Private Use: Fortigate-50B, 4.00-MR3, NAT/IPsec-VPN/SSL-VPN
Private Use: Fortigate-50B, 4.00-MR3, NAT/IPsec-VPN/SSL-VPN
daveywavey
New Contributor

followed the instructions in the Fortigate Knowledge Centre article ID 3568, this VIP group is used in policy 99 below as (set dstaddr " XBOX360" ) I posted both policy 99 = NAT Open and 98 = NAT Moderate, if you want to chose which one to use LIVE with. Just de-activate and activate the ones you want to use. config firewall policy edit 97 set srcintf " internal" set dstintf " external" set srcaddr " Xbox 360" set dstaddr " all" set action accept set schedule " Always Full Open" set service " HTTP" " XBox 360 Live Ports" set profile-status enable set logtraffic enable set comments " Policy For Xbox 360" set profile " IPS AV" set nat enable next edit 98 set srcintf " external" set dstintf " internal" set srcaddr " all" set dstaddr " Xbox 360" set action accept set status disable set schedule " Always Full Open" set service " HTTP" " XBox 360 Live Ports" set profile-status enable set logtraffic enable set comments " This rule helps XBox Live get a NAT reading of Moderate" set profile " IPS AV" set nat enable set fixedport enable next edit 99 set srcintf " external" set dstintf " internal" set srcaddr " all" set dstaddr " XBOX360" set action accept set schedule " Always Full Open" set service " XBox 360 Live Ports" " HTTP" set profile-status enable set logtraffic enable set comments " This rule helps XBox Live get a NAT reading of Open" set profile " IPS AV" set nat enable set fixedport enable next end
Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
Forti OS 4.0: FLG_100B-v400-build0705 (4.3.7) FWF_80CM-v400-build0665 (4.3.15) Forti OS 5.0: FWF_90D-v500-build0228 (5.0.3)
Not applicable

Thanks guys, for this. This did the job for me too!!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors