Fortinet FortiGate Series Administration Manual page 467

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

Firewall Virtual IP
FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
2 Select Create New.
3 Enter the following information and select OK.
Name
pool-1
Interface
DMZ
IP
10.1.3.1-10.1.3.254
Range/Subnet
To create a Virtual IP with port translation only
1 Go to Firewall > Virtual IP > Virtual IP.
2 Select Create New.
3 Enter the following information and select OK.
Name
server-1
External
Internal
Interface
Type
Static NAT
External IP
172.16.1.1
Address/Range
Note this address is the same as the server address.
Mapped IP
172.16.1.1.
Address/Range
Port Forwarding Enable
Protocol
TCP
External Service
8080
Port
Map to Port
80
To create a firewall policy
Add an internal to dmz firewall policy that uses the virtual IP to translate the destination
port number and the IP pool to translate the source addresses.
1 Go to Firewall > Policy.
2 Select Create New.
3 Configure the firewall policy:
Source Interface/Zone
Source Address
Destination
Interface/Zone
Destination Address
Schedule
Service
Action
4 Select NAT.
5 Select OK.
Double NAT: combining IP pool with virtual IP
internal
10.1.1.0/24
dmz
server-1
always
HTTP
ACCEPT
467

Advertisement

Table of Contents
loading

Table of Contents