Adding A Load Balance Port Forwarding Virtual Ip - Fortinet Fortigate-5000 series Administration Manual

Hide thumbs Also See for Fortigate-5000 series:
Table of Contents

Advertisement

Firewall Virtual IP
3
4

Adding a load balance port forwarding virtual IP

1
2
3
FortiGate Version 3.0 MR4 Administration Guide
01-30004-0203-20070102
Service
Action
Select NAT.
Select OK.
Connections to 192.168.37.4 on the Internet are mapped to 10.10.10.42 through
10.10.10.44 on a private network. The IP address mapping is determined by the
FortiGate unit's load balancing algorithm. Ports 80 to 83 on 192.168.37.4 are
mapped to 8000 through 8003, in sequence. The computers on the Internet are
unaware of this translation and see a single computer at 192.168.37.4 rather than
a FortiGate unit with a private network behind it.
Figure 159:Load balance virtual IP port forwarding for an IP address range and a port
range example
To add a load balance virtual IP for an IP address range
Go to Firewall > Virtual IP > Virtual IP.
Select Create New.
Use the following procedure to add a virtual IP that allows users on the Internet to
connect to a web server on the DMZ network. In our example the external
interface of the FortiGate unit is connected to the Internet and the dmz1 interface
is connected to the DMZ network.
Name
External Interface
Type
External IP Address/Range The Internet IP address of the web server.
Map to IP/IP Range
HTTP
ACCEPT
Load_Bal_VIP_port_forward
external
Load Balance
The external IP address must be a static IP address obtained
from your ISP for your web server. This address must be a
unique IP address that is not used by another host and
cannot be the same as the IP address of the external
interface the virtual IP will be using. However, the external IP
address must be routed to the selected interface. The virtual
IP address and the external IP address can be on different
subnets. When you add the virtual IP, the external interface
responds to ARP requests for the external IP address.
The IP address of the servers on the internal network. Define
the range by entering the first address of the range in the first
field and the last address of the range in the second field.
Configuring virtual IPs
265

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents