Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luca1994
New Contributor III

loopback for internet traffic

Hello team,

 

I configured a loopback with WAN role and ssigned it a public ip address. Now I need the client network to go out to the outside world with the ip address of the loopback. To do this just make policies that have the client interface as the source and the loopback as the destination and enable the NAT flag in the policies or is it mandatory to configure an ip-pool? Thanks for the support

19 REPLIES 19
luca1994
New Contributor III

Hi @AEK , in my case my actual WAN interface is MPLS interface (172.x.x.x). For the policy i use this interface as outgoing interface with traffic with IP pool containing the loopback's IP address.

 

Is correct in this way?

 

Thank you very much

BR

AEK

Yes that's right.

AEK
AEK
AEK

For your provider you have both 172.x.x.x and the public IP, so you can NAT with the public IP on the same interface and it is accepted as source IP by your provider.

AEK
AEK
luca1994
New Contributor III

Thank you very much for the clarification @AEK 
The firewall doesn't navigate and if I do a traceroute to 8.8.8.8 (for example) it stops on the MPLS router interface, so I really think the problem is with the provider who provides the MPLS circuit. What are your thoughts on this?

AEK

When using ping or traceroute from FGT in such situation you probably have te specify the source IP.

Does it work from an internal host?

AEK
AEK
luca1994
New Contributor III

no, from internal host coming from the mpls network ping and traceroute are not working. the traffic flow should be as follows:

 

internal host --> df gw (another firewall no Fortigte) --> mpls circuit --> Fortigate loopback --> Fortigate MPLS IP interface (NAT ip pool) ---> MPLS router --> internet

 

Thanks
BR

AEK

Then I'm wondering why the provider asked for loopback. You may check if there is bgp.

AEK
AEK
luca1994
New Contributor III

I looked into it and bpg is on the mpls circuit.

 

Thanks

BR

AEK
SuperUser
SuperUser

The you have to push the required dgp configuration. I guess you may ask it from the provider.

AEK
AEK
Toshi_Esumi
SuperUser
SuperUser

Your MPLS/Internet provider should have a config example for Cisco router or other major routers. Getting it and interpreting&converting it to FGT config should be easier.

 

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors