Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zeno
New Contributor

open ports in fortigate

Hi everyone

 

i have been asked to move production server to dmz another range 

Actual Navision production web server is located on p-web-nav01(192.168.16.0/24)they want to move  it to DMZ (192.168.18.0/24)

We have two services there, one is the NAV Web Client Service and the second is NAV Help Server. Is it possible to have this server accessible from internal network on port 49000 ??

Tasks :

1- open port 443 to internet (all navision users should be able to connect ) 

2- opens Communication on port HTTP: 49000 to Internet and Internal Network (all nav Users should be able to connect)

3- opens communication between NavServer  and WebServer  - 7076

 

can anyone help me with this i don't wanna make any mistake when making the changes 

 

Thanks in Advance 

2 REPLIES 2
sw2090
SuperUser
SuperUser

VIP + policy will do this for you. There is Cookbook articles on this...

 

Beware: if you redirect 443 you will not be able to https access the FGT from outside anymore unless you change the port the fgt uses.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
zeno
New Contributor

so what I have to do is :

1- virtual ip:  100.82.90.86_192.168.18.62_443 (tcp: 443 --> 443)

  ipv4 policy:  100.82.90.86_192.168.18.62_443 /  / services https , tcp_8443

2- virtual ip: 100.82.90.86_192.168.18.62_49000 (tcp: 49000 --> 49000)

ipv4 policy: 100.82.90.86_192.168.18.62_49000 / / services 49000

 

please correct me if i'm wrong

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors