Firewall Virtual IP
Configuring virtual IPs
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
377
•
3
Select
NAT
.
4
Select
OK
.
Adding static NAT port forwarding for an IP address range and a port range
Ports 80 to 83 of addresses 192.168.37.4 to 192.168.37.7 on the Internet are mapped to
ports 8000 to 8003 of addresses 10.10.10.42 to 10.10.10.44 on a private network.
Attempts to communicate with 192.168.37.5, port 82 from the Internet, for example, are
translated and sent to 10.10.10.43, port 8002 by the FortiGate unit. The computers on the
Internet are unaware of this translation and see a single computer at 192.168.37.5 rather
than a FortiGate unit with a private network behind it.
Figure 232: Static NAT virtual IP port forwarding for an IP address range and a port range
example
To add static NAT virtual IP port forwarding for an IP address range and a port
range
1
Go to
Firewall > Virtual IP > Virtual IP
.
2
Select
Create New
.
3
Use the following procedure to add a virtual IP that allows users on the Internet to
connect to a web server on the DMZ network. In this example, the external interface of
the FortiGate unit is connected to the Internet and the dmz1 interface is connected to
the DMZ network.
Source Interface/Zone
wan1
Source Address
All (or a more specific address)
Destination
Interface/Zone
dmz1
Destination Address
Port_fwd_NAT_VIP
Schedule
always
Service
HTTP
Action
ACCEPT
Name
Port_fwd_NAT_VIP_port_range
External Interface
external
Type
Static NAT
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...