Problem with Fortigate 300

Problem with Fortigate 300

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Problem with Fortigate 300 Joutsen 12-18-2006
Posted by Joutsen on December 18, 2006, 2:24 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm hoping someone can help me with this one.

I have a Fortigate 300 with Internal, External and DMZ/HA ports.

I have 2 servers connected with each other in a Microsoft Cluster
Services (MSCS) cluster in the Internal subnet. There are also a number
of other non-clustered servers in the subnet.

There are web servers in the DMZ/HA subnet.

When the firewall is configured to allow this (for testing), External
traffic can connect successfully to the clustered servers in the
Internal subnet. Internal traffic can also connect to these 2 servers.

The problem is that DMZ/HA source traffic cannot connect to the
clustered server, even if all DMZ traffic is allowed to connect to
Internal. The web servers in DMZ can connect successfully to all other
servers in Internal, but still cannot connect to the MSCS cluster.

Machines in the DMZ cannot connect (or even ping) the cluster virtual
IP addresses, or the nodes' individual IP addresses.

For temporary testing, the fortigate is configured to not restrict any
access between Internal, DMZ and External.

When we had a Fortigate 100A, this was not a problem; everything worked
fine.

Does anyone know if there are problems with the Fortigate 300 not
allowing any connections between DMZ/HA and Internal when connecting to
Windows clustered servers? The Fortigate firmware is at: Fortigate-300
2.80,build489,051027

Thanks.
Joutsen


Similar ThreadsPosted
FORTIGATE 200 PORT FORDWARDING DNS PROBLEM August 27, 2005, 7:26 am
Fortigate 3.0 November 5, 2005, 9:00 am
Fortigate FG-60 and SIP April 1, 2006, 5:47 pm
Fortigate FG-60 and SIP April 1, 2006, 5:54 pm
anyone using ips on a fortigate June 27, 2007, 10:05 am
Fortigate/virusScan May 10, 2005, 4:26 pm
Fortigate 60 and PPPoE DSL April 23, 2006, 12:03 am
Cisco pix or Fortigate? January 18, 2007, 3:35 pm
Fortigate is greate but not so great. March 29, 2006, 8:52 am
Fortigate 60 connection limit? September 20, 2006, 10:29 pm

The site map in XML format XML site map

Contact Us | Privacy Policy