Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SteFiD93
New Contributor

open port on 50E

Hello to all, I recently took possession of this fantastic 50E firewall, we had it in the company where it was managed by more competent external people.

i tried to configure the ports as in every guide in the network also watching many videos, but nothing i can't get anything to work. being at home I don't have a corporate internet .. so I have a dynamic ip and a modem .. with the affected port open.

my firmware version is 6.2.5, I create a VIP with:

NAME:mywebserver

0.0.0.0 External IP (I also tried to put the IP of the modem to which I then connect externally 192.168.1.204 or my external IP)

192.168.0.106 Internal IP (my server web)

Wan1 For interface (modem internet) (i tried to put lan and any)

TCP PORT 8182

 

then I created an IPv4 rule:

 

Incoming Interface: Wan1

Out Interface : lan

Source: all

destination: "mywebserver" (I also tried to put all)

Schedules: Always

Service: ALL (I also tried to change the server ports by putting 443 and then selecting HTTPS)

Firewall NAT: ON (I also tried with OFF)

Security profile: All off (here I have a big problem I can not remove the ssl but I did not check the certificates)

 

ok, yes I tried in all ways without results, obviously the firewall is practically new without any changes .. I formatted it .. changed password connected to the modem and connected to the pc.

can someone help me? did i do the right procedure? before that i used another firewall and everything worked (it was from another brand)

 

 

 

 

I am a computer enthusiast, I come from Italy, and I love to experiment and get informed
I am a computer enthusiast, I come from Italy, and I love to experiment and get informed
5 REPLIES 5
boneyard
Valued Contributor

does your modem allow traffic from external to internal at all? often on home equipment you need port forwarding on them.

 

how did you connect the firewall in your network? which ports in which networks?

SteFiD93

yes yes, then I connected the wan1 to the modem lan, then the modem gave me an ip address 192.168.1.204, if I type that ip connected with the cable to the modem and not to the firewall it gives me the fortigate page. here I have opened the ports on the modem as well, telling him to allow all traffic on 192.168.1.204 this thing works if I connect the server without going through the firewall. ok later I connect my pc to the firewall and type 192.168.0.99 and access the page .. I configure as per the internet guides .. on the ip 192.168.0.106 which is the server concerned ... but nothing works
I am a computer enthusiast, I come from Italy, and I love to experiment and get informed
I am a computer enthusiast, I come from Italy, and I love to experiment and get informed
boneyard
Valued Contributor

drawings help a lot in situations like this. is below what you setup?

 

 

from where are you trying to reach the VIP 192.168.1.204:8182 ? where is your PC connected at that moment.

SteFiD93

thank you so much! I solved, thanks to your image and looking in detail at others I was referring to I realized that I had to remove the lan group and I set every rule for each lan port of the firewall, now I'm not at home so I can't take pictures or create images .. but I basically solved it like this: 1) i told wan1 to create a second virtual ip 192.168.1.205 where i can't access the fortigate (that i do with 192.168.1.204) 2) i created a subnet for lan2 (where i connected the server) and told him the server was 192.168.3.2 3) i created a VIP saying that the ip 192.168.2.3 (firewall) had to exit as 192.168.1.205 (modem) 4) I created a rule on the firewall and one on the modem to open the affected port. on the modem I said to open the port on the ip 192.168.1.205 and it works! now on my external ip I see what I want! and internally I have created firewall rules to communicate between the various lan (192.168.2.1/192.168.3.1/ecc)
I am a computer enthusiast, I come from Italy, and I love to experiment and get informed
I am a computer enthusiast, I come from Italy, and I love to experiment and get informed
SteFiD93

ok now that i'm home post photos of how i solved!

now this is how it works:

wan

lan/wan

VIP

Policy

 

 

 

before it was like this and it didn't work:

 

 

I am a computer enthusiast, I come from Italy, and I love to experiment and get informed
I am a computer enthusiast, I come from Italy, and I love to experiment and get informed
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors