You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将指向NLB的流量路由至同子网FortiGate防火墙实例?

解决方案:让EKS NLB入站流量经过FortiGate防火墙

一、现有配置的核心错误分析

1. 防火墙策略ID冲突

你提供的配置中两条防火墙策略都使用edit 1,导致第一条test策略被第二条test2覆盖,公网到NLB的入站流量实际被阻断。

2. 静态路由配置逻辑错误

将网关指向NLB IP完全不符合流量转发逻辑,FortiGate的路由应该确保自身能访问NLB子网,同时让出站流量通过公网接口返回互联网。


二、修正后的FortiGate配置

1. 修复防火墙策略(区分双向流量)

config system interface
edit port1
set vdom "root"
set alias public
set mode dhcp
set allowaccess ping https ssh fgfm
next
edit port2
set vdom "root"
set alias private
set mode dhcp
set allowaccess ping https ssh fgfm probe-response
next
end

config firewall policy
# 公网→NLB的入站流量策略
edit 1
set name "Internet_to_NLB"
set srcintf "port1"
set dstintf "port2"
set srcaddr "all"
set dstaddr "all"  # 建议替换为NLB私网IP的地址对象,缩小范围
set action accept
set schedule "always"
set service "ALL"
set logtraffic all
next
# NLB→公网的回程流量策略
edit 2
set name "NLB_to_Internet"
set srcintf "port2"
set dstintf "port1"
set srcaddr "all"  # 建议替换为NLB私网IP的地址对象
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
set logtraffic all
next
end

# 修正静态路由
config router static
    # 公网出站默认路由(port1通过DHCP获取的话可省略,这里显式配置确保生效)
    edit 1
        set dst 0.0.0.0/0
        set gateway <公有子网IGW_IP>
        set device "port1"
    next
    # 如果port2和NLB不在同子网,添加子网路由(同子网则省略)
    edit 2
        set dst <NLB所在子网CIDR>
        set device "port2"
    next
end

2. 添加DNAT转发规则(核心)

要让互联网流量通过FortiGate转发到NLB,需要配置VIP做地址转换:

config firewall vip
edit "NLB_VIP"
set extip <FortiGate绑定的EIP>
set mappedip <NLB私网IP>
set extintf "port1"
next
end

config firewall policy
edit 3
set name "DNAT_to_NLB"
set srcintf "port1"
set dstintf "port2"
set srcaddr "all"
set dstaddr "NLB_VIP"
set action accept
set schedule "always"
set service "ALL"
set nat enable
set logtraffic all
next
end

三、AWS侧网络架构调整(解决路由限制)

AWS不允许在IGW或公有子网路由表中直接将单个NLB私网IP作为路由目标,因此需要调整架构:

  1. 将原公网NLB改为内部NLB
    登录AWS控制台,修改目标NLB的Scheme为internal,使其仅在VPC内可访问,记录NLB的私网IP。
  2. 配置子网路由表
    修改NLB所在子网的路由表,添加一条路由:目标0.0.0.0/0,下一跳为FortiGate的port2私网IP,确保EKS节点的回程流量能通过FortiGate返回互联网。
  3. 绑定EIP到FortiGate port1
    给FortiGate的port1分配弹性公网IP,作为互联网访问的唯一入口。

四、验证步骤

  1. 从互联网访问FortiGate的EIP,检查是否能正常访问EKS应用
  2. 查看FortiGate的流量日志,确认入站/回程流量均经过防火墙
  3. 测试EKS应用的出站访问,确保回程路径正常

内容的提问来源于stack exchange,提问作者Adeel Shahzad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 00:05:32