Fortinet Fortigate-5000 series Administration Manual page 259

Hide thumbs Also See for Fortigate-5000 series:
Table of Contents

Advertisement

Firewall Virtual IP
3
4
1
2
3
4
FortiGate Version 3.0 MR4 Administration Guide
01-30004-0203-20070102
Use the following procedure to add a virtual IP that allows users on the Internet to
connect to three individual web servers on the DMZ network. In our example the
external interface of the FortiGate unit is connected to the Internet and the dmz1
interface is connected to the DMZ network.
Name
External Interface
Type
External IP Address/Range The Internet IP address range of the web servers.
Map to IP/IP Range
Figure 153:Virtual IP options; static NAT virtual IP with an IP address range
Select OK.
To add a static NAT virtual IP with an IP address range to a firewall policy
Add a external to dmz1 firewall policy that uses the virtual IP so that when users
on the Internet attempt to connect to the server IP addresses, packets pass
through the FortiGate unit from the external interface to the dmz1 interface. The
virtual IP translates the destination addresses of these packets from the external
IP to the DMZ network IP addresses of the servers.
Go to Firewall > Policy and select Create New.
Configure the firewall policy:
Source Interface/Zone
Source Address Name
Destination Interface/Zone dmz1
Destination Address Name static_NAT_range
Schedule
Service
Action
Select NAT.
Select OK.
static_NAT_range
external
Static NAT
The external IP addresses must be static IP addresses
obtained from your ISP for your web server. These
addresses must be unique IP addresses that are not used by
another host and cannot be the same as the IP addresses of
the external interface the virtual IP will be using. However,
the external IP addresses must be routed to the selected
interface. The virtual IP addresses and the external IP
address can be on different subnets. When you add the
virtual IP, the external interface responds to ARP requests
for the external IP addresses.
The IP address range of the servers on the internal network.
Define the range by entering the first address of the range in
the first field and the last address of the range in the second
field.
external
All (or a more specific address)
always
HTTP
ACCEPT
Configuring virtual IPs
259

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents