Protecting a web server on the DMZ network
49
1. Con
fi
guring the FortiGate unit’s DMZ interface
2. Adding virtual IPs
3. Creating security policies
4. Results
Protecting a web server on the DMZ network
In the following example, a web server is connected to a DMZ network. An internal-
to-DMZ security policy allows internal users to access the web server using an
internal IP address (10.10.10.22). A WAN-to-DMZ security policy hides the internal
address, allowing external users to access the web server using a public IP address
(172.20.120.22).
Internet
WAN
1
172.20.120.22
FortiGate
DMZ
DMZ Network
Web Server
10.10.10.22
LAN
Internal Network
THE FOR
TIGA
TE COOKBOOK
Summary of Contents for FortiGate 1U
Page 1: ...FortiOS 5 0 4 1U Models ...
Page 3: ......
Page 4: ...2 ...
Page 5: ...3 QUICKSTART GUIDE FortiGate 1U QuickStart Guide ...
Page 14: ......
Page 15: ...The FortiGate Cookbook Recipes for Success with your FortiGate THE FORTIGATE COOKBOOK ...
Page 16: ......
Page 20: ......
Page 24: ......
Page 88: ......
Page 158: ......
Page 198: ......
Page 229: ...Using redundant OSPF routing over IPsec VPN 209 THE FORTIGATE COOKBOOK ...
Page 235: ...Using redundant OSPF routing over IPsec VPN 215 THE FORTIGATE COOKBOOK ...
Page 238: ......
Page 239: ...About Fortinet High Performace Network Security Q3 2013 ...
Page 253: ...PRODUCT GUIDE Product Guide ...
Page 265: ......