Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hoiyi88
New Contributor

outbound NAT use ip pools seem not work

Inbound use VIP to do mapping is ok.

Outbound use IP Pools to set but failed.

Outbound ip is different with original ip.

Thanks.

10 REPLIES 10
Bunce
New Contributor

If associated with a VIP rule, I'm pretty sure it will use the VIP IP for outgoing as well.

hoiyi88
New Contributor

There have one server with 3 DMZ IPs .   

3 DMZ IPs will use different port to do signal and media.  It seems VIP IP rules outgoing IP is different with original IPs.

 

if one server with 1 DMZ ip with VIP mapping. the outgoing IP is same with original IP.

Bunce
New Contributor

If this traffic is for Video Conferencing are you sure the VC system is setup correctly?   NAT raises a number of difficulties with H323 / SIP protocols etc, especially if teamed with Fortinet's Session helpers.

 

It's pretty much universally accepted to disable these helpers on Fortigate units as they always cause trouble - that would be my first recommendation and then report back with the latest results, ideally with a log capture:

http://socpuppet.blogspot.com.au/search?q=diag+debug+flow 

Bunce
New Contributor

In reference to my initial reply, this is worth a read:

https://forum.fortinet.com/tm.aspx?m=112623 

emnoc
Esteemed Contributor III

yeah, start with diag debug flow and see what's going, what policy is being used etc....Traffic mapped to a DNAT inboun VIP and policy will ALWAYS use the mapped IP for the returned traffic.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
hoiyi88
New Contributor

Yes, inbound VIP can always map to outbound.  

 

If the connection is come from external network it is work fine.

 

but i meet problem is if the connection is from internal network to the VIP, the VIP doesn't use correct IP to out.

 

 

Thanks.

hoiyi88

I export firewall rules and the VIP setting as below:

set id 0 set comment '' set type static-nat set extip 211.x.x.x set extintf "wan1" set arp-reply enable set nat-source-vip disable set portforward disable set gratuitous-arp-interval 0 set color 0 set mappedip 192.168.1.100

 

Please advise .

Thanks.

emnoc
Esteemed Contributor III

The diag debug flow is  your friend, the above just shows VIP settings the fwpolicy(s) allows for movement of traffic.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rwpatterson
Valued Contributor III

Double check the policy order. If a policy is before your NAT policies for that server and the server traffic matches it, this is where the outbound traffic will flow.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors