Hi, I'm facing a problem that I have a Windows host which connects to
the Fortinet VPN gateway and this host has Internet over VPN and etc.
works great. However now I want this VPN connection "share" with other
device , so I choose Network Adapter se...
Hi, Here is my setup HQ has FG-501E with FortiOS 5.6.5Branch has FG-61E
with FortiOS 5.6.6 So I have two sites, HQ and Branch, I wanted to
extend one of the HQ VLANs (vlan 892) to Branch, actually it works more
or less, but there is a problem in bran...
Hi, I wanted to apply set match-vip enable to policy and it turns out
FortiOS doesn't have such a command ! When it was removed, and how can I
now accomplish hair-pin NAT ? This is what I get in cli: # set match-vip
enable command parse error before ...
Hi, On any recipies I can see that when hair-pinning (NAT reflection,
U-turn NAT) is needed the Virtual IP interface must be set to ANY. Is it
only option ? Or is it possible to set up hair-pinning when Virtual IP
has interface set to WAN ? Also is i...
Hi, I'm relatively new to FortiGate, my background is Cisco ASA, but I
got convinced to FortiNet by my friend and we bought a pair of FG-501E
as our main firewall. Ok,so I have a active-standby cluster. FortiOS
ver. is 5.6.5 I created VDOM for my mai...
Thanks I will try to do that. Question aside, can the vxlan-interface
bridge has IP assigned ? Because currently for computers on that VLAN
the HQ (172.16.92.1) is default gateway, and I would rather want them go
through my wan1. So I was thinking to...
OK so I did it, yes I needed remove policy and then I was able to change
interface. However the U-turn NAT doesn't work. Virtual IP is a standard
static NAT. Then I have Policy which allow specific geoIPs access this
service from outside. Note the 17...
OKThis topic can be closed. I connected a server to FW and actually ping
worked from server. So the conclusion is that means that is not possible
to test from firewall internal interfaces IPs.