Link to home
Start Free TrialLog in
Avatar of TripapHoniC
TripapHoniCFlag for United States of America

asked on

Open FortiGate 60C for 1 IP

Hey community.  I was hoping someone could point me in the direction of a tutorial or job aid for allowing all traffic from WAN to Internal for 1 IP address without putting it in the DMZ.  In this situation I'm using a FortiGate 60C with the latest patched firmware.

Thanks.
Avatar of skullnobrains
skullnobrains

you can always create a VIP for that machine, and a port redirection on a port range that contain all the existing ports from 0-65k

it is better but likely not functionally required if the outgoing connections for this machine are instructed to be NATed using that same VIP (external address)

beware that this somehow defeats the purpose of having a firewall. if you give information about what you are trying to achieve using this setup, i may be able to give some better advice
Avatar of TripapHoniC

ASKER

Thanks skullnobrains.

This company is a gaming facility and wishes to have 1 of their Xbox 360 units exposed to the Internet to see if there are Microsoft Live services which are not making it through their firewall.
ASKER CERTIFIED SOLUTION
Avatar of skullnobrains
skullnobrains

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks skullnobrains.  I already had something similar to what you suggested set up in the firewall but was having issues with the traffic routing for some reason.  I ended up calling a Fortinet engineer and they found that HTTPS traffic was included in a previously created policy which was preventing the routing to the Xbox working properly.  After we eliminated the superfluous policy it worked properly.
so i wasn't much of a help, but good to see you worked it out.
thanks for posting back.

note that the fortinet lets you see the number of time each rule is hit, and also displays the rule name in the live connections display which can come very handy next time you run into such a situation.

best regards