Hello team,
I configured a loopback with WAN role and ssigned it a public ip address. Now I need the client network to go out to the outside world with the ip address of the loopback. To do this just make policies that have the client interface as the source and the loopback as the destination and enable the NAT flag in the policies or is it mandatory to configure an ip-pool? Thanks for the support
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @AEK , in my case my actual WAN interface is MPLS interface (172.x.x.x). For the policy i use this interface as outgoing interface with traffic with IP pool containing the loopback's IP address.
Is correct in this way?
Thank you very much
BR
Yes that's right.
For your provider you have both 172.x.x.x and the public IP, so you can NAT with the public IP on the same interface and it is accepted as source IP by your provider.
Thank you very much for the clarification @AEK
The firewall doesn't navigate and if I do a traceroute to 8.8.8.8 (for example) it stops on the MPLS router interface, so I really think the problem is with the provider who provides the MPLS circuit. What are your thoughts on this?
Created on 01-12-2024 08:07 AM Edited on 01-12-2024 08:08 AM
When using ping or traceroute from FGT in such situation you probably have te specify the source IP.
Does it work from an internal host?
no, from internal host coming from the mpls network ping and traceroute are not working. the traffic flow should be as follows:
internal host --> df gw (another firewall no Fortigte) --> mpls circuit --> Fortigate loopback --> Fortigate MPLS IP interface (NAT ip pool) ---> MPLS router --> internet
Thanks
BR
Then I'm wondering why the provider asked for loopback. You may check if there is bgp.
I looked into it and bpg is on the mpls circuit.
Thanks
BR
The you have to push the required dgp configuration. I guess you may ask it from the provider.
Your MPLS/Internet provider should have a config example for Cisco router or other major routers. Getting it and interpreting&converting it to FGT config should be easier.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.