Configuring virtual IPs
Firewall Virtual IP
FortiGate Version 4.0 Administration Guide
376
01-400-89802-20090424
3
Use the following procedure to add a virtual IP that allows users on the Internet to
connect to a web server on the DMZ network. In our example, the wan1 interface of the
FortiGate unit is connected to the Internet and the dmz1 interface is connected to the
DMZ network.
Figure 231: Virtual IP options: Static NAT port forwarding virtual IP for a single IP address
and a single port
4
Select
OK
.
To add static NAT virtual IP port forwarding for a single IP address and a single port
to a firewall policy
Add a wan1 to dmz1 firewall policy that uses the virtual IP so that when users on the
Internet attempt to connect to the web server IP addresses, packets pass through the
FortiGate unit from the wan1 interface to the dmz1 interface. The virtual IP translates the
destination addresses and ports of these packets from the external IP to the dmz network
IP addresses of the web servers.
1
Go to
Firewall > Policy
and select
Create New
.
2
Configure the firewall policy:
Name
Port_fwd_NAT_VIP
External Interface
wan1
Type
Static NAT
External IP
Address/Range
The Internet IP address of the web server.
The external IP address is usually a static IP address obtained from
your ISP for your web server. This address must be a unique IP
address that is not used by another host and cannot be the same
as the IP address of the external interface the virtual IP will be
using. However, the external IP address must be routed to the
selected interface. The virtual IP address and the external IP
address can be on different subnets. When you add the virtual IP,
the external interface responds to ARP requests for the external IP
address.
Mapped IP
Address/Range
The IP address of the server on the internal network. Since there is
only one IP address, leave the second field blank.
Port Forwarding
Selected
Protocol
TCP
External Service Port
The port traffic from the Internet will use. For a web server, this will
typically be port 80.
Map to Port
The port on which the server expects traffic. Since there is only one
port, leave the second field blank.
Содержание Gate 60D
Страница 678: ...Reports Log Report FortiGate Version 4 0 Administration Guide 678 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 704: ...Index FortiGate Version 4 0 Administration Guide 704 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 705: ...www fortinet com...
Страница 706: ...www fortinet com...