Solved

Dual Wan Fortgate setup for SBS 2008

Posted on 2011-09-12
6
1,322 Views
Last Modified: 2012-06-27
Can anyone share a working setup for a Fortigate (60C-80C)  (FortiOS 4 MR2) for an SBS 2008 server.
Especially to make the firewall accept SMTP traffic (25) on both Wan Interfaces?
When using only one Wan you can use a VIP (Virtual IP) to forward all traffic on port 25 to the server but you can do this only once per port.
There is an example on Fortigates knowledge base but this assumes a seperate SMTP server in the DMZ.
Can it be done without the DMZ? Any examples?

http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD31240&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=23603459&stateId=0%200%2023605076

I have made all the ISP side changes with 2x diffrently weighted MX (and corresponding A records) pointing at the correct Permanent IP addresses on Wan1 and Wan2?

Any suggestions would be appreciated.

Olaf
0
Comment
Question by:Olaf De Ceuster
  • 3
  • 3
6 Comments
 
LVL 4

Expert Comment

by:iworks-uworks
Comment Utility
In the VIP rule you must specify the external WAN IP for each rule:

NAME: SMTP_WAN1
Internaface: WAN1
External IP: x.x.x.x
Internal IP: 192.168.0.2
Port: 25 ->25

NAME: SMTP_WAN2
Internaface: WAN2
External IP: y.y.y.y
Internal IP: 192.168.0.2
Port: 25 ->25

Let me know if you have any problems with that.
0
 
LVL 22

Author Comment

by:Olaf De Ceuster
Comment Utility
Thank you iworks,

Tried that already.
Seems the fortigate only lets me make one VIP per port.
Wan1 with forward 25-25 no problem
Wan2 : Duplicate entry found.
Olaf
0
 
LVL 4

Accepted Solution

by:
iworks-uworks earned 500 total points
Comment Utility
Olafdc,
Please refer to the picture I've attached. You need to make sure you specify the EXTERNAL IP address for both VIPs. Don't leave it at 0.0.0.0, put in the actual external IP and it should work like the picture I've attached. Carefully review the IP addresses and Ports. DualWan-port25
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 22

Author Comment

by:Olaf De Ceuster
Comment Utility
Already been down that path. No Go...duplicate entry.
Might update firmware and try again.
Will let you know.
Thank you heaps so far.
Olaf
0
 
LVL 4

Expert Comment

by:iworks-uworks
Comment Utility
What firmware are using on what box? Can you post a screen shot of your first VIP with the external IP blurred or changed and also what you have entered for the 2nd rule before you hit OK and get the error message?
0
 
LVL 22

Author Comment

by:Olaf De Ceuster
Comment Utility
Update to: v4.0,build5840,110715 (MR2) did the trick.
Two instances on port 25 allowed. Yeeaah.
Was starting to doubt myself.
Thanks heaps for your help.
Olaf
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now