Hi, we have a 2 servers which are NAT'ed on 2 public IP's on a branch office. Here in our main office, I can connect remotely to the branch office using their public IP's i.e rdp, ssh, etc
My issue is, inside the branch office definitely you're going to use their LAN or private IP in connecting to each other, but whenever I used both of their public IP's to each other, it doesn't work.
Server1 connects to Server2 or vice versa (via private IP) = good
Server1 connects to Server2 or vice versa (via public IP) = no go
Though I know it is better and faster to use the private IP, I'm just curious if is it possible to use the public IP?
Thanks
Jeff
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Jeff,
its possible, but due to the change of behauviour between 5.2 and 5.4 you have to use hairpinning ... (https://en.wikipedia.org/wiki/Hairpinning)
So you have to create a policy with:
source interface: internal
source ip: your internal network
destination Interface: internal
destination ip: your mapped IP, which you normally use with the wan to lan policy (i know, looks strange ... ;) )
Greez
Claus
-
300C x1, 200E x4, 240D x2, 200D x4, 101E x2, 100E x4, 100D x12, 80C x2, 70D x2, 61E x2, 60E x2, 60D x30, 60C x24, 60B x9, 50E x20, 50B x17, 40C x17, 30E x3
FortiMail VMs
FortiAnalyzer VMs
FortiSandbox (testrun)
@net@work
Thanks, yes, been reading this hairpinning and will do some tests about this.
Thanks
Jeff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1092 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.