Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fsv99er
New Contributor

unreachable wan ip adress from internal lan

Hy, Since a few weeks we have a fortigate 100D. Everything worked very fine. But now we have a big Problem. We have a WAN Ip Adress 212.xxx.xxx.xxx. This IP is reachable from the Internet. All works fine. But if my Device has an internel LAN IP Adress 192.xxx.xxx.xxx we cant reach the WAN IP Adress. What can i do that the WAN IP adress ist reachable from the LAN ? Is this a routing Problem ?
17 REPLIES 17
emnoc
Esteemed Contributor III

Go to the WebGUI or CLI and check and set the allowaccess for ping for that interface e.g ( cli ) config sys interface edit wan1 set allowaccess ping end If you have this already than, diag debug flow is your friend. it would probably show something similar " trace_id=21 msg=" iprope_in_check() check failed, drop" "

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
fsv99er
New Contributor

hy, thanks for your fast reply. i did the allowacces ping.... but the problem is the same the diagnose debug flow shows this: id=13 trace_id=703 msg=" vd-root received a packet(proto=6, 192.168.xxx.xxx:21347->212.xxx.xxx.xxx:443) from lan." id=13 trace_id=703 msg=" allocate a new session-001b981a" id=13 trace_id=703 msg=" find SNAT: IP-192.168.0.9(from IPPOOL), port-443" id=13 trace_id=703 msg=" VIP-192.168.0.9:443, outdev-lan" id=13 trace_id=703 msg=" DNAT 212.xxx.xxx.xxx:443->192.168.0.9:443" id=13 trace_id=703 msg=" find a route: gw-192.168.0.9 via lan" id=13 trace_id=703 msg=" use addr/intf hash, len=3" id=13 trace_id=703 msg=" Denied by forward policy check" i there a problem ?
TheJaeene
Contributor

Hi, do you want to reach an internal Server (VIP) via the external Address? Regards, Jan
fsv99er
New Contributor

Yes ! With this external adress i will reach an internal ip. Its works ! But with an internal ip i cant reach the external WAN adress
TheJaeene
Contributor

A dirty solution: If your external IP is static you can build a Hairpin NAT/Policy " VIP-Server" Portforwarding (bound to internal) " external IP" 443 -> MAP TO " Internal Server IP" 443 Policy: Internal -> Internal Internal Network -> to " VIP Server" 443
emnoc
Esteemed Contributor III

guys, the answer is right in front of you;
" Denied by forward policy check"
Your missing a fwpolicy.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
TheJaeene

Blind :D
TheJaeene

@fsv99er Emnoc had some coffee.. me not :D Forget what I just wrote. Check your Firewall Rules (or post them here along with the vip definitions)
fsv99er
New Contributor

I need your help. I create a " Vip Server" in Firewall Object - Addresses ... with the ip of the internal server In the Policy i say lan to vip server or what ?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors