Sunday, February 2, 2020

Fortigate VIP's don't show up as options when making a policy

Hi All,

I am teaching myself some networking in my home labs (hopefully this doesn't violate rule #1). I have two separate networks, one with a 60D and one with an 80C. On the 60D, I am running 5.2, on the 80c, 5.6.

The 60D, I was able to setup a policy to allow all external to reach the VIP I made that port forwards port 80, to an IP in the DMZ.

Went to go do the same thing on the 80c, but when I get to selecting the destination, I can't for the life of me get the new VIP I made there to show up in web gui or from cli. I have done some googlefuing. and found two posts that match identical symptoms, but in both cases they seem to be the result of upgrading a previous verision of fortios while trying to keep the prior config.

https://community.spiceworks.com/topic/1973368-fortigate-virtual-ips-not-selectable

https://forum.fortinet.com/tm.aspx?m=152197

Mine is a new config from scratch. Another post https://forum.fortinet.com/tm.aspx?m=152731 they mention disabling central nat. Tried doing this, but still no luck.

Things I have tried doing so far:
Remaking the VIP (numerous times).

Ensuring the interface the vip is bound to matches what I am trying to declare in the policy (dmz interface).

Any other suggestions for things I can try?



No comments:

Post a Comment