Adding An Ip Pool; Ip Pools For Firewall Policies That Use Fixed Ports; Ip Pools And Dynamic Nat - Fortinet FortiGate 50A Installation And Configuration Manual

Fortinet fortigate installation and configuration guide
Hide thumbs Also See for FortiGate 50A:
Table of Contents

Advertisement

IP pools

Adding an IP pool

IP Pools for firewall policies that use fixed ports

IP pools and dynamic NAT

162
To add an IP pool
1
Go to Firewall > IP Pool.
2
Select the interface to which to add the IP pool.
3
Select New to add a new IP pool to the selected interface.
4
Enter the Start IP and End IP addresses for the range of addresses in the IP pool.
The start IP and end IP must define the start and end of an address range. The start
IP must be lower than the end IP. The start IP and end IP must be on the same subnet
as the IP address of the interface that you are adding the IP pool.
5
Select OK to save the IP pool.
Figure 14: Adding an IP Pool
Some network configurations do not operate correctly if a NAT policy translates the
source port of packets used by the connection. NAT translates source ports to keep
track of connections for a particular service. You can select fixed port for NAT policies
to prevent source port translation. However, selecting fixed port means that only one
connection can be supported through the firewall for this service. To be able to support
multiple connections, you can add an IP pool to the destination interface, and then
select dynamic IP pool in the policy. The firewall randomly selects an IP address from
the IP pool and assigns it to each connection. In this case the number of connections
that the firewall can support is limited by the number of IP addresses in the IP pool.
You can use IP pools for dynamic NAT. For example, your organization might have
purchased a range of Internet addresses but you might have only one Internet
connection on the external interface of your FortiGate unit.
You can assign one of your organization's Internet IP addresses to the external
interface of the FortiGate unit. If the FortiGate unit is operating in NAT/Route mode, all
connections from your network to the Internet appear to come from this IP address.
Firewall configuration
Fortinet Inc.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents