Koozali.org: home of the SME Server

Obsolete Releases => SME Server 7.x => Topic started by: dilligaf on April 26, 2007, 06:01:25 PM

Title: server only behind fortigate
Post by: dilligaf on April 26, 2007, 06:01:25 PM
Hi,
I am trying to get my SMEServer to work behind a firewall.

(the SMEServer hosts our website, and our e-mail)
Previously it was in server gateway mode, and services worked as expected.

For testing/evaluation purpose of the fortigate I need this configuration.

I have set the SMEServer as "server only"
and set up the fortigate  and from a client pc, can surf the net, send mail etc.

But do not recieve e-mail, and external people can not access the website.

On the fortigate firewall there is a policy to forword smtp, http, and https traffice from external interface to the SMEServer internal interface.

What am I missing?
Title: Re: server only behind fortigate
Post by: m on May 01, 2007, 11:17:05 PM
Quote from: "dilligaf"
Hi,

On the fortigate firewall there is a policy to forword smtp, http, and https traffice from external interface to the SMEServer internal interface.

What am I missing?


If you have created  correct "Virtual IP" entries and setup correct policies for each Virtual IP  in "External(WAN)->Internal" it works. I have setup this many times.
Title: Re: server only behind fortigate
Post by: dilligaf on May 01, 2007, 11:22:35 PM
Quote from: "mweinber"
Quote from: "dilligaf"
Hi,

On the fortigate firewall there is a policy to forword smtp, http, and https traffice from external interface to the SMEServer internal interface.

What am I missing?


If you have created  correct "Virtual IP" entries and setup correct policies for each Virtual IP  in "External(WAN)->Internal" it works. I have setup this many times.


Hi Michael, If you would not mind emailing me off list (dan@willcraft.com) I would sure appreciate a little more feedback on your experience with this.
Thanks,
Title: Re: server only behind fortigate
Post by: m on May 01, 2007, 11:43:45 PM
Quote from: "dilligaf"

Hi Michael, If you would not mind emailing me off list

Sure.