Fortinet FortiGate Series Administration Manual page 458

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

Configuring virtual IPs
458
3 Use the following procedure to add a virtual IP that allows users on the Internet to
connect to a web server on the DMZ network. In our example, the wan1 interface of the
FortiGate unit is connected to the Internet and the dmz1 interface is connected to the
DMZ network.
Figure 257: Virtual IP options: Static NAT port forwarding virtual IP for a single IP address
and a single port
Name
External Interface
Type
External IP
Address/Range
Mapped IP
Address/Range
Port Forwarding
Protocol
External Service Port
Map to Port
4 Select OK.
To add static NAT virtual IP port forwarding for a single IP address and a single port
to a firewall policy
Add a wan1 to dmz1 firewall policy that uses the virtual IP so that when users on the
Internet attempt to connect to the web server IP addresses, packets pass through the
FortiGate unit from the wan1 interface to the dmz1 interface. The virtual IP translates the
destination addresses and ports of these packets from the external IP to the dmz network
IP addresses of the web servers.
1 Go to Firewall > Policy and select Create New.
2 Configure the firewall policy:
Port_fwd_NAT_VIP
wan1
Static NAT
The Internet IP address of the web server.
The external IP address is usually a static IP address obtained from
your ISP for your web server. This address must be a unique IP
address that is not used by another host and cannot be the same
as the IP address of the external interface the virtual IP will be
using. However, the external IP address must be routed to the
selected interface. The virtual IP address and the external IP
address can be on different subnets. When you add the virtual IP,
the external interface responds to ARP requests for the external IP
address.
The IP address of the server on the internal network. Since there is
only one IP address, leave the second field blank.
Selected
TCP
The port traffic from the Internet will use. For a web server, this will
typically be port 80.
The port on which the server expects traffic. Since there is only one
port, leave the second field blank.
FortiGate Version 4.0 MR1 Administration Guide
Firewall Virtual IP
01-410-89802-20090903
http://docs.fortinet.com/
Feedback

Advertisement

Table of Contents
loading

Table of Contents