Adding Policies With Virtual Ips; Ip Pools - Fortinet FortiGate 50A Installation And Configuration Manual

Fortinet fortigate installation and configuration guide
Hide thumbs Also See for FortiGate 50A:
Table of Contents

Advertisement

Firewall configuration

Adding policies with virtual IPs

IP pools

FortiGate-50A Installation and Configuration Guide
Use the following procedure to add a policy that uses a virtual IP to forward packets.
To add a policy with a virtual IP
1
Go to Firewall > Policy.
2
Select the type of policy that you want to add.
The source interface must match the interface selected in the External Interface
list.
The destination interface must match the interface connected to the network with
the Map to IP address.
3
Use the following information to configure the policy.
Source
Destination
Schedule
Service
Action
NAT
Authentication
Log Traffic
Anti-Virus & Web filter
4
Select OK to save the policy.
An IP pool (also called a dynamic IP pool) is a range of IP addresses added to a
firewall interface. If you add IP pools to an interface, you can select Dynamic IP Pool
when you configure a policy with the destination set to this interface. You can add an
IP pool if you want to add NAT mode policies that translate source addresses to
addresses randomly selected from the IP pool rather than being limited to the IP
address of the destination interface.
For example, if you add an IP pool to the internal interface, you can select Dynamic IP
pool for Ext->Int policies.
You can add multiple IP pools to any interface but only the first IP pool is used by the
firewall.
This section describes:
Adding an IP pool
IP Pools for firewall policies that use fixed ports
IP pools and dynamic NAT
Select the source address from which users can access the server.
Select the virtual IP.
Select a schedule as required.
Select the service that matches the Map to Service that you selected
for the port-forwarding virtual IP.
Set action to ACCEPT to accept connections to the internal server.
You can also select DENY to deny access.
Select NAT if the firewall is protecting the private addresses on the
destination network from the source network.
Optionally select Authentication and select a user group to require
users to authenticate with the firewall before accessing the server
using port forwarding.
Select these options to log port-forwarded traffic and apply antivirus
and web filter protection to this traffic.
IP pools
161

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents

Save PDF