Hot!DMZ with public subnet not working from wan

Author
orbiter2001
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/05/14 07:01:22
  • Status: offline
2020/05/15 00:09:10 (permalink)
0

DMZ with public subnet not working from wan

I give FortiGate 60F a try but I stuck with the DMZ configuration.
 
I have a subnet of public ip addresses configured on the DMZ Interface, and I have connected my Web-Server to this DMZ. I also have configured some Virtual IP's for devices which are located in the internal network and port forwarding is needed.
 
Now I'm trying to access all this from WAN and the Web-Server is not working. The Virtual IP's are working, so I think my problem is maybe NAT, but I have switched of NAT.
 
From internal network I have access to the Web-Server.
 
Is there another system configuration which I missed?

Attached Image(s)

#1

5 Replies Related Threads

    TheJaeene
    Silver Member
    • Total Posts : 111
    • Scores: 10
    • Reward points: 0
    • Joined: 2010/01/06 00:56:49
    • Status: offline
    Re: DMZ with public subnet not working from wan 2020/05/15 02:44:33 (permalink)
    0
    Hi Orbiter,
     
     
     
    could you please tell us if you splitted the public Subnet you have to WAN and DMZ?
    To fully understand the issue we need the adresses (could be obfuscated of course)
     
    Most of the times you bind the public IPs on the WAN IF and then you DNAT them via VIP to the respective (private) Address in the DMZ.
     
    If you have a separate Public Subnet on your DMZ IF, the Provider needs to route that Traffic to one of the WAN Interfaces IPs.
    Sounds like that may be your problem.
     
     
     
    post edited by TheJaeene - 2020/05/15 03:04:16
    #2
    orbiter2001
    New Member
    • Total Posts : 4
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/05/14 07:01:22
    • Status: offline
    Re: DMZ with public subnet not working from wan 2020/05/15 03:22:24 (permalink)
    0
    Thanks for your answer. 
     
    WAN1
    IP Address: xx.174.184.62/29
    Gateway: xx.174.184.57
     
    DMZ
    IP Address: xx.174.189.33/29
     
    The DMZ Subnet xx.174.189.32/29 is fully routed to the WAN 1 IP Address.
     
    I Also tried with a computer in the WAN1 network to access the web-server in dmz, this is not working. the Gateway of the computer was set to the WAN1 ip address of the fortigate. so if the routing of the public subnet from provider woudl be wrong then I should be able to access the web-server in this scenario.
    #3
    orbiter2001
    New Member
    • Total Posts : 4
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/05/14 07:01:22
    • Status: offline
    Re: DMZ with public subnet not working from wan 2020/05/15 03:32:15 (permalink)
    0
    Additional:
    On the Web-Server in the DMZ i can ping WAN1 ip address of FortiGate but I cannot ping the computer which is in the WAN network.
    #4
    TheJaeene
    Silver Member
    • Total Posts : 111
    • Scores: 10
    • Reward points: 0
    • Joined: 2010/01/06 00:56:49
    • Status: offline
    Re: DMZ with public subnet not working from wan 2020/05/15 03:46:09 (permalink)
    0
    How did you bind the VIP´s just to their respective nearest IF (Internal).
     
    Just a quick idea:
    Please try to disable the arp-reply on the VIPs via CLI
     
    set arp-reply disable
     
    EDIT:
     
    Ahh, I see your VIPs are also external.. I thought they were Internal to DMZ.
    Then forget my ARP reply Idea ;-)
    But please note that sometimes VIPs without a policy tend to genrerate arp replies for them.
     
    Best thing to find out why the traffic is broken would be to do a debug flow.
     
    Are you running FOS 6.2.4 already? 
    post edited by TheJaeene - 2020/05/15 03:54:47
    #5
    orbiter2001
    New Member
    • Total Posts : 4
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/05/14 07:01:22
    • Status: offline
    Re: DMZ with public subnet not working from wan 2020/05/25 05:05:33 (permalink)
    0
    I did factory reset. After reconfiguring everything worked fine. Maybe I did some misconfiguring because I had to figure out how it works with this product.
     
    thanks for your hints.
    #6
    Jump to:
    © 2020 APG vNext Commercial Version 5.5