Inbound use VIP to do mapping is ok.
Outbound use IP Pools to set but failed.
Outbound ip is different with original ip.
Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If associated with a VIP rule, I'm pretty sure it will use the VIP IP for outgoing as well.
There have one server with 3 DMZ IPs .
3 DMZ IPs will use different port to do signal and media. It seems VIP IP rules outgoing IP is different with original IPs.
if one server with 1 DMZ ip with VIP mapping. the outgoing IP is same with original IP.
If this traffic is for Video Conferencing are you sure the VC system is setup correctly? NAT raises a number of difficulties with H323 / SIP protocols etc, especially if teamed with Fortinet's Session helpers.
It's pretty much universally accepted to disable these helpers on Fortigate units as they always cause trouble - that would be my first recommendation and then report back with the latest results, ideally with a log capture:
In reference to my initial reply, this is worth a read:
yeah, start with diag debug flow and see what's going, what policy is being used etc....Traffic mapped to a DNAT inboun VIP and policy will ALWAYS use the mapped IP for the returned traffic.
PCNSE
NSE
StrongSwan
Yes, inbound VIP can always map to outbound.
If the connection is come from external network it is work fine.
but i meet problem is if the connection is from internal network to the VIP, the VIP doesn't use correct IP to out.
Thanks.
I export firewall rules and the VIP setting as below:
set id 0 set comment '' set type static-nat set extip 211.x.x.x set extintf "wan1" set arp-reply enable set nat-source-vip disable set portforward disable set gratuitous-arp-interval 0 set color 0 set mappedip 192.168.1.100
Please advise .
Thanks.
The diag debug flow is your friend, the above just shows VIP settings the fwpolicy(s) allows for movement of traffic.
PCNSE
NSE
StrongSwan
Double check the policy order. If a policy is before your NAT policies for that server and the server traffic matches it, this is where the outbound traffic will flow.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.