Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

virtual ip problem

heres the scenario I have a webserver (x.x.x.y) on the internal network and when i type in the address http:\\x.x.x.y from any of my internal machines, i get the webpage displayed the way i want it. I want to create a virtual IP on the firewall so that I could access the same page externally. i have the my domain name (xyz.com) served up on the internet and it uses the ip address of the firewall. waht i mean is when i go to https:\\xyz.com i get the FG60 login page. i want to use http:\\xyz.com and want it to go to the webserver on internal network. n e suggestions... I am kind of desperate right now. i have the virutal ip confgured for FTP service and its working fine. (from the internet use ftp:\\xyz.com) Need some help here.
7 REPLIES 7
Not applicable

Hi, Yo did not mention what version you have installed. If it is ver 3 then all you nee to do is go to system> admin >setting and change the port you manage the fortigate with...lets say 444 then you wouldlog on to your fortinet https://x.x.x.x:444 then go to VIP and add ext > x.x.x.x > internal server. Enjoy
Not applicable

thanks shlomi and javier. shlomi, i have 3.0 version now. i upgarded yest night. changed it as u said but still a no go. i still dont get access to the page. the change of port worked coz now i have to use http://xyz.com:444 to get to the fortigate page i have the virtual ip policy. wan to internal ipaddress (also tried 0.0.0.0) to internal address port 80 to port 80
Not applicable

Use the virtual IP as you want but remember... if you type http://YourPublicIp, you are going to see always your FG unit, cause it has his http access available on port 80. What you have to do is this, Virtual Ip Map over ports: Change your external port to whatever you want for exemple 8080 and then your internal port 80 associated to private address of the WebServer x.x.x.y . So any packets incoming from port 8080 will be redirected to x.x.x.y to port 80. And then type from a public network in a web browser http://xyz.com:8080 Use the same about https (i don' t remember exactly what port uses)
RickP
New Contributor

I had a great big long post half-written, but something much simpler occurred to me. What if you disable HTTP and HTTPS access to the Administration GUI on your WAN port? That would certainly stop the admin login from coming up! You shouldn' t have HTTP access enabled there anyway. Give it a go. My confusion comes from the fact that I haven' t seen the virtual IP feature used with the IP address the WAN port already is using. I' ve always had a second IP solely for the server in question.
Not applicable

rick the login does not come up anymore. it just fails with " the request URL could not be retrieved" While trying to retrieve the URL: xyz.com:443 the followin error was encountered" Connection failed. what i dont understand what is making the router to try to forward the request to port 443 and then fail. i only type in http:\\www.xyz.com
RickP
New Contributor

What did you enter to create the virtual IP? The other thing is that you need to create a policy. External/All to Internal/VIP, where VIP is the name you gave to the virtual IP. Unless traffic is specifically allowed, it is denied by the FortiGate unit. The lack of policy would not explain the weird remapping to port 443 though.
Not applicable

Is there anyone who could try the scenario i am facing a problem with and see if it works for them. At this point i want to see if its the firmware/router or just something on my network. i would really appreciate it. thanks
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors