Dual Wan Fortgate setup for SBS 2008

Can anyone share a working setup for a Fortigate (60C-80C)  (FortiOS 4 MR2) for an SBS 2008 server.
Especially to make the firewall accept SMTP traffic (25) on both Wan Interfaces?
When using only one Wan you can use a VIP (Virtual IP) to forward all traffic on port 25 to the server but you can do this only once per port.
There is an example on Fortigates knowledge base but this assumes a seperate SMTP server in the DMZ.
Can it be done without the DMZ? Any examples?

http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD31240&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=23603459&stateId=0%200%2023605076

I have made all the ISP side changes with 2x diffrently weighted MX (and corresponding A records) pointing at the correct Permanent IP addresses on Wan1 and Wan2?

Any suggestions would be appreciated.

Olaf
LVL 22
Olaf De CeusterAsked:
Who is Participating?

[Webinar] Streamline your web hosting managementRegister Today

x
 
iworks-uworksConnect With a Mentor Commented:
Olafdc,
Please refer to the picture I've attached. You need to make sure you specify the EXTERNAL IP address for both VIPs. Don't leave it at 0.0.0.0, put in the actual external IP and it should work like the picture I've attached. Carefully review the IP addresses and Ports. DualWan-port25
0
 
iworks-uworksCommented:
In the VIP rule you must specify the external WAN IP for each rule:

NAME: SMTP_WAN1
Internaface: WAN1
External IP: x.x.x.x
Internal IP: 192.168.0.2
Port: 25 ->25

NAME: SMTP_WAN2
Internaface: WAN2
External IP: y.y.y.y
Internal IP: 192.168.0.2
Port: 25 ->25

Let me know if you have any problems with that.
0
 
Olaf De CeusterAuthor Commented:
Thank you iworks,

Tried that already.
Seems the fortigate only lets me make one VIP per port.
Wan1 with forward 25-25 no problem
Wan2 : Duplicate entry found.
Olaf
0
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

 
Olaf De CeusterAuthor Commented:
Already been down that path. No Go...duplicate entry.
Might update firmware and try again.
Will let you know.
Thank you heaps so far.
Olaf
0
 
iworks-uworksCommented:
What firmware are using on what box? Can you post a screen shot of your first VIP with the external IP blurred or changed and also what you have entered for the 2nd rule before you hit OK and get the error message?
0
 
Olaf De CeusterAuthor Commented:
Update to: v4.0,build5840,110715 (MR2) did the trick.
Two instances on port 25 allowed. Yeeaah.
Was starting to doubt myself.
Thanks heaps for your help.
Olaf
0
All Courses

From novice to tech pro — start learning today.