Adding Dynamic Virtual Ips - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

Configuring virtual IPs

Adding dynamic virtual IPs

460
External IP
Address/Range
Mapped IP
Address/Range
Port Forwarding
Protocol
External Service Port
Map to Port
4 Select OK.
To add static NAT virtual IP port forwarding for an IP address range and a port
range to a firewall policy
Add a external to dmz1 firewall policy that uses the virtual IP so that when users on the
Internet attempt to connect to the web server IP addresses, packets pass through the
FortiGate unit from the external interface to the dmz1 interface. The virtual IP translates
the destination addresses and ports of these packets from the external IP to the dmz
network IP addresses of the web servers.
1 Go to Firewall > Policy and select Create New.
2 Configure the firewall policy:
Source Interface/Zone
Source Address
Destination
Interface/Zone
Destination Address
Schedule
Service
Action
3 Select NAT.
4 Select OK.
Adding a dynamic virtual IP is similar to adding a virtual IP. The difference is that the
External IP address must be set to 0.0.0.0 so the External IP address matches any IP
address.
To add a dynamic virtual IP
1 Go to Firewall > Virtual IP > Virtual IP.
2 Select Create New.
3 Enter a name for the dynamic virtual IP.
The external IP addresses are usually static IP addresses obtained
from your ISP. This addresses must be unique, not used by another
host, and cannot be the same as the IP address of the external
interface the virtual IP will be using. However, the external IP
addresses must be routed to the selected interface. The virtual IP
addresses and the external IP address can be on different subnets.
When you add the virtual IP, the external interface responds to ARP
requests for the external IP addresses.
The IP addresses of the server on the internal network. Define the
range by entering the first address of the range in the first field and
the last address of the range in the second field.
Selected
TCP
The ports that traffic from the Internet will use. For a web server,
this will typically be port 80.
The ports on which the server expects traffic. Define the range by
entering the first port of the range in the first field and the last port of
the range in the second field. If there is only one port, leave the
second field blank.
external
All (or a more specific address)
dmz1
Port_fwd_NAT_VIP_port_range
always
HTTP
ACCEPT
FortiGate Version 4.0 MR1 Administration Guide
Firewall Virtual IP
01-410-89802-20090903
http://docs.fortinet.com/
Feedback

Advertisement

Table of Contents
loading

Table of Contents