Allowing LAN Internal Network To A DMZ Device
User asked me to allow lan network to access a dmz device ip: 10.10.10.50
lan ip-range is 192.168.100.110-192.168.100.210 gateway: 192.168.100.99
1- i went to addresses > create new> i didnt find a place to create an object for dmz device 10.10.10.50
so the first question question how do i create an object and give it a name and an ip address. what i found is to create subnet and ip range and this is not what i was looking for.
i need to create this dmz object because i want to allow lan only to this dmz machine. how do i do that in forti.
2- what i did for now for testing is allowing lan to all dmz network, even this didnt work and i dont know why...
i went to policy and objects > addresses > created 2 new ip range pbjects
name dmz-network and name internal-network ip ranges.
then i went to ipv4 policy > create new
incoming interface: internal
outgoing interface: dmz
source: internal network
when i went to a pc in lan tried to ping 10.10.10.50
there was no ping?
how do i go from here? please assist.