?
Solved

Dual Wan Fortgate setup for SBS 2008

Posted on 2011-09-12
6
Medium Priority
?
1,328 Views
Last Modified: 2012-06-27
Can anyone share a working setup for a Fortigate (60C-80C)  (FortiOS 4 MR2) for an SBS 2008 server.
Especially to make the firewall accept SMTP traffic (25) on both Wan Interfaces?
When using only one Wan you can use a VIP (Virtual IP) to forward all traffic on port 25 to the server but you can do this only once per port.
There is an example on Fortigates knowledge base but this assumes a seperate SMTP server in the DMZ.
Can it be done without the DMZ? Any examples?

http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD31240&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=23603459&stateId=0%200%2023605076

I have made all the ISP side changes with 2x diffrently weighted MX (and corresponding A records) pointing at the correct Permanent IP addresses on Wan1 and Wan2?

Any suggestions would be appreciated.

Olaf
0
Comment
Question by:Olaf De Ceuster
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 4

Expert Comment

by:iworks-uworks
ID: 36530590
In the VIP rule you must specify the external WAN IP for each rule:

NAME: SMTP_WAN1
Internaface: WAN1
External IP: x.x.x.x
Internal IP: 192.168.0.2
Port: 25 ->25

NAME: SMTP_WAN2
Internaface: WAN2
External IP: y.y.y.y
Internal IP: 192.168.0.2
Port: 25 ->25

Let me know if you have any problems with that.
0
 
LVL 22

Author Comment

by:Olaf De Ceuster
ID: 36532783
Thank you iworks,

Tried that already.
Seems the fortigate only lets me make one VIP per port.
Wan1 with forward 25-25 no problem
Wan2 : Duplicate entry found.
Olaf
0
 
LVL 4

Accepted Solution

by:
iworks-uworks earned 2000 total points
ID: 36533144
Olafdc,
Please refer to the picture I've attached. You need to make sure you specify the EXTERNAL IP address for both VIPs. Don't leave it at 0.0.0.0, put in the actual external IP and it should work like the picture I've attached. Carefully review the IP addresses and Ports. DualWan-port25
0
WatchGuard's M Series Appliances - Miecom Approved

WatchGuard's newest M series appliances were put to the test by Miercom.  We had great results and outperformed all of our competitors in both stateless and stateful traffic throghput scenarios! Ready to see how your UTM appliance stacked up? Download the Miercom Report!

 
LVL 22

Author Comment

by:Olaf De Ceuster
ID: 36534019
Already been down that path. No Go...duplicate entry.
Might update firmware and try again.
Will let you know.
Thank you heaps so far.
Olaf
0
 
LVL 4

Expert Comment

by:iworks-uworks
ID: 36534027
What firmware are using on what box? Can you post a screen shot of your first VIP with the external IP blurred or changed and also what you have entered for the 2nd rule before you hit OK and get the error message?
0
 
LVL 22

Author Comment

by:Olaf De Ceuster
ID: 36534312
Update to: v4.0,build5840,110715 (MR2) did the trick.
Two instances on port 25 allowed. Yeeaah.
Was starting to doubt myself.
Thanks heaps for your help.
Olaf
0

Featured Post

WatchGuard's M Series Appliances - Miecom Approved

WatchGuard's newest M series appliances were put to the test by Miercom.  We had great results and outperformed all of our competitors in both stateless and stateful traffic throghput scenarios! Ready to see how your UTM appliance stacked up? Download the Miercom Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question