Adding Static Nat Port Forwarding For A Single Ip Address And A Single Port - Fortinet Fortigate-5000 series Administration Manual

Hide thumbs Also See for Fortigate-5000 series:
Table of Contents

Advertisement

Configuring virtual IPs

Adding static NAT port forwarding for a single IP address and a single port

260
The IP address 192.168.37.4, port 80 on the Internet is mapped to 10.10.10.42,
port 8000 on a private network. Attempts to communicate with 192.168.37.4,
port 80 from the Internet are translated and sent to 10.10.10.42, port 8000 by the
FortiGate unit. The computers on the Internet are unaware of this translation and
see a single computer at 192.168.37.4, port 80 rather than a FortiGate unit with a
private network behind it.
Figure 154:Static NAT virtual IP port forwarding for a single IP address and a single
port example
To add static NAT virtual IP port forwarding for a single IP address and a
single port
1
Go to Firewall > Virtual IP > Virtual IP.
2
Select Create New.
3
Use the following procedure to add a virtual IP that allows users on the Internet to
connect to a web server on the DMZ network. In our example the external
interface of the FortiGate unit is connected to the Internet and the dmz1 interface
is connected to the DMZ network.
Name
External Interface
Type
External IP Address/Range The Internet IP address of the web server.
Map to IP/IP Range
Port Forwarding
Protocol
External Service Port
Map Port
Port_fwd_NAT_VIP
external
Static NAT
The external IP address must be a static IP address obtained
from your ISP for your web server. This address must be a
unique IP address that is not used by another host and
cannot be the same as the IP address of the external
interface the virtual IP will be using. However, the external IP
address must be routed to the selected interface. The virtual
IP address and the external IP address can be on different
subnets. When you add the virtual IP, the external interface
responds to ARP requests for the external IP address.
The IP address of the server on the internal network. Since
there is only one IP address, leave the second field blank.
Selected
TCP
The port traffic from the Internet will use. For a web server,
this will typically be port 80.
The port on which the server expects traffic. Since there is
only one port, leave the second field blank.
FortiGate Version 3.0 MR4 Administration Guide
Firewall Virtual IP
01-30004-0203-20070102

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents