Configuring virtual IPs
Firewall Virtual IP
FortiGate Version 4.0 Administration Guide
378
01-400-89802-20090424
4
Select
OK
.
To add static NAT virtual IP port forwarding for an IP address range and a port
range to a firewall policy
Add a external to dmz1 firewall policy that uses the virtual IP so that when users on the
Internet attempt to connect to the web server IP addresses, packets pass through the
FortiGate unit from the external interface to the dmz1 interface. The virtual IP translates
the destination addresses and ports of these packets from the external IP to the dmz
network IP addresses of the web servers.
1
Go to
Firewall > Policy
and select
Create New
.
2
Configure the firewall policy:
3
Select
NAT
.
4
Select
OK
.
Adding dynamic virtual IPs
Adding a dynamic virtual IP is similar to adding a virtual IP. The difference is that the
External IP address must be set to 0.0.0.0 so the External IP address matches any IP
address.
To add a dynamic virtual IP
1
Go to
Firewall > Virtual IP > Virtual IP
.
2
Select
Create New
.
3
Enter a name for the dynamic virtual IP.
External IP
Address/Range
The external IP addresses are usually static IP addresses obtained
from your ISP. This addresses must be unique, not used by another
host, and cannot be the same as the IP address of the external
interface the virtual IP will be using. However, the external IP
addresses must be routed to the selected interface. The virtual IP
addresses and the external IP address can be on different subnets.
When you add the virtual IP, the external interface responds to ARP
requests for the external IP addresses.
Mapped IP
Address/Range
The IP addresses of the server on the internal network. Define the
range by entering the first address of the range in the first field and
the last address of the range in the second field.
Port Forwarding
Selected
Protocol
TCP
External Service Port
The ports that traffic from the Internet will use. For a web server,
this will typically be port 80.
Map to Port
The ports on which the server expects traffic. Define the range by
entering the first port of the range in the first field and the last port of
the range in the second field. If there is only one port, leave the
second field blank.
Source Interface/Zone
external
Source Address
All (or a more specific address)
Destination
Interface/Zone
dmz1
Destination Address
Port_fwd_NAT_VIP_port_range
Schedule
always
Service
HTTP
Action
ACCEPT
Содержание Gate 60D
Страница 678: ...Reports Log Report FortiGate Version 4 0 Administration Guide 678 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 704: ...Index FortiGate Version 4 0 Administration Guide 704 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 705: ...www fortinet com...
Страница 706: ...www fortinet com...