- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
view real source ip in fortigate aws
Hii all,
i have a topology in aws environmet like this :
NLB -> fortigate -> TGW -> server.
Our nlb already NATing ip public to ip private, so fortigate only detect ip source private from nlb.
so my question is could we seeing ip public source behind NLB in fortigate ?
thank.
- Labels:
-
FortiGateCloud
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Rifqi,
I think this could be related to a NLB AWS behavior. If you see the Private IP from NLB as the source, it is because that's how NLB forwards traffic to the FortiGate. If NLB were to include the "Real" public IP in the header instead of the private one when forwarding traffic to the FortiGate, you would then see the public IP on FortiGate.
I think that behavior is because you are doing Nating on NLB.
I hope that helps.
Regards,
Fortinet TAC Senior Engineer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hii marin,
if our NLB do not nating and keep using ip public for source, then our fortigate could detect real ip source who access our servers ?
thanks,
Regards,
Rifqi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
