- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
lan vip
hi, I have a problem with Fortigate 80f. I made interface number 2 as WAN and did port forwarding with VIP but I can't make it work. It gets an IP address as WAN and I can connect from outside, but the VIP rule doesn't work. The VIP rules on the WAN and LAN sides work, I write the rule and do the VIP process correctly.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi,
so basically now you have 2 wan ports, wan1 and wan2 ? or, please share more info about your setup.
try enabling NAT for traffic , wan2 > lan ( vip ) and see if it works.
Created on ‎02-24-2025 11:15 PM Edited on ‎02-24-2025 11:16 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i have 2 wan ports, wan1 and lan2.
wan1 vip works without any problems, there are 5 rules. Exchange and rdp etc.
VIP on LAN 2 does not work, I can connect to the external IP address I assigned to LAN2, but the VIP operation does not work.
I enabled nat but it didn't help.
Created on ‎02-24-2025 11:40 PM Edited on ‎02-24-2025 11:44 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
can you confirm that traffic is entering lan2 ( wan2 ) interface ?
do a , diag sniffer packet lan2 'host SRC' 4 0 l , to confirm.
can you also please share the config of the rules and vip ? show firewall policy <> and show firewall vip <> for this new one?
L.E. also the routing table would be quite important, get router info routing-table static ( assuming that there are static routes for wan connection, otherwise please use all instead of static )
Created on ‎02-25-2025 12:23 AM Edited on ‎02-26-2025 07:24 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Evet, WAN (LAN2) IP adresi ile dışarıdan fortigate arayüzüne erişiyorum. Mobil telefonun dışından 176.xx.xx IP adresine erişerek fortigate gui'yi açabilirim.
KameraWan(lan4) -----> KameraLan(lan2)
1- fw politikası
FortiGate-80F (10) #
yapılandırma güvenlik duvarı politikasını göster
düzenle 10
adı ayarla "CameraVip"
uuid'yi ayarla fa53a266-dd84-51ef-6f1d-e046bdc28c72
srcintf'yi ayarla "internal4"
dstintf'yi ayarla "internal2"
eylemi kabul et
srcaddr'ı ayarla "all"
dstaddr'ı ayarla "CamerasVip"
zamanlamayı ayarla "always"
hizmetini ayarla "Camera"
logtraffic all
sonraki
son
2- vip - Bunları tek bir grup altında birleştirdim
3-Yönlendirme
yönlendiriciyi statik olarak
düzenle 6
ağ geçidini 176.xx.xxx.xxx olarak ayarla
önceliği ayarla 4
aygıtı "internal4" olarak ayarla
sonraki
son
Created on ‎02-25-2025 05:04 AM Edited on ‎02-25-2025 05:05 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would suspect the fact that the return/reply traffic exists the other WAN1 interface since internal4 ( WAN2 ) isnt the primary one, but you stated that you enabled NAT for this rule id 10 and still didnt work.
The only thing that comes to mind, the service "Camera" contains all the ports for the VIPs ? You could set service to all , since you are doing already a DNAT port to port .
L.E. just to confirm, internal2 is the port where your devices in network 192.168.111.X can be reached, correct ?
Created on ‎02-25-2025 05:26 AM Edited on ‎02-25-2025 05:29 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I currently have company that works with Juniper SRX, I am thinking of switching to Fortigate. The cameras work stably on Juniper SRX with the same ports. Internal 2 camera network is 111.0/24, rule is defined from int1 to int2 and ping is successful, if I disable the rule, ping is unsuccessful. There is a problem on the VIP side but I can't solve it.
I tried all the ports but it still won't connect.
Created on ‎02-25-2025 05:31 AM Edited on ‎02-25-2025 05:32 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
most likely, there is something wrong with the VIP itself, since I'm not seeing in the last column in your screenshot any hits.
can you please do a show firewall vip <> of one of the objects and let's focus on that.
can you please also confirm that the extip in the VIP is the same IP of internal4 ( WAN2 ) ?
L.E. you can also DM me with the real IP address and I can test with a telnet IP:port .
Created on ‎02-25-2025 05:59 AM Edited on ‎02-26-2025 07:25 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
a
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @social ,
If you are using internal2 as WAN2 facing the Internet, the firewall policy for the new VIP should be using internal2 as the source interface, and internal4 as the destination interface.
Jerry
