Tom's Hardware > Forum > General Networking > Firewall > FORTIGATE 200 PORT FORDWARDING DNS PROBLEM

FORTIGATE 200 PORT FORDWARDING DNS PROBLEM

Forum General Networking : Firewall - FORTIGATE 200 PORT FORDWARDING DNS PROBLEM

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: comp.security.firewalls (More info?)

 

I have a problem with a Fortinet Fortigate appliance.

In the local network there is a Windows 2000 Server machine runing DNS
server and IIS with a local IP 192.168.10.7 ( hosting a website) this
machine is at a DMZ behind a Fortigate 200 Firewall, and is reachable
from the internet using "Static Nat" from a public IP to the internal
IP of this Windows Server.

I recently install a new Linux machine on the same LAN with IP
192.168.10.10 running Apache on default port 80 running a website and
want this website can be viewed from the internet, so i tought that
port redirection was the solution and setup a "Port Forwarding" rule on
the Fortigate opening a 8088 port on external that redirects to the
internal ip ( 192.168.10.10 ) on port 80 ( http ).

Unfortunately we have just only one public IP , and the port
redirection did not work, may be because the "Static Nat" that makes
work the website on the windows box supersedes the Port Forwarding
rule.
So I disable the Static Nat to the Windows box and create Port
Forwarding from external to ports 80tcp, 53tcp, 53udp. My linux site on
port 8088 works, the windows site works ... but after a time the Domain
Name that the Windows serves goes down from Internet. When I enable
NAT again to the Win box, the DNS works again!.

What i´m doing wrong?.

Sponsored Links
Register or log in to remove.
Tom's Hardware > Forum > General Networking > Firewall > FORTIGATE 200 PORT FORDWARDING DNS PROBLEM
Go to:

There are 1240 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them