12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FortiGuard Center<br />

System Maintenance<br />

3 Select Use override push IP and enter the IP address of the external interface of<br />

the NAT device.<br />

4 Do not change the push update port unless UDP port 9443 is blocked or used by<br />

other services on your network.<br />

5 Select Apply.<br />

The <strong>FortiGate</strong> unit sends the override push IP address and port to the FDN. The<br />

FDN now uses this IP address and port for push updates to the <strong>FortiGate</strong> unit on<br />

the internal network. Push updates will not actually work until you add a virtual IP<br />

to the NAT device so that the NAT device accepts push update packets and<br />

forwards them to the <strong>FortiGate</strong> unit on the internal network.<br />

Note: If the external IP address or external service port changes, add the changes to the<br />

Use override push configuration and select Apply to update the push information on the<br />

FDN.<br />

To add a port forwarding virtual IP to the <strong>FortiGate</strong> NAT device<br />

Configure the NAT device to use port forwarding to forward push update<br />

connections from the FDN to the <strong>FortiGate</strong> unit on the internal network.<br />

1 Go to Firewall > Virtual IP and select Create New.<br />

2 Add a port forwarding virtual IP that maps the external interface of the NAT device<br />

to the IP address of the <strong>FortiGate</strong> unit on the internal network using the push<br />

update UDP port.<br />

Name<br />

Add a name for the Virtual IP.<br />

External Interface The interface on the NAT device that connects to the Internet.<br />

Type<br />

Static NAT.<br />

External IP<br />

Address/Range<br />

Mapped IP<br />

Address/Range<br />

Port Forwarding<br />

Protocol<br />

External Service<br />

Port<br />

Map to Port<br />

3 Select OK.<br />

The IP address that the FDN connects to send push updates to the<br />

<strong>FortiGate</strong> unit on the Internal network. This would usually be the IP<br />

address of the external interface of the NAT device. This IP address<br />

must be the same as the FortiGuard Center push update override IP of<br />

the <strong>FortiGate</strong> unit on the internal network.<br />

The IP address of the <strong>FortiGate</strong> unit on the Internal network.<br />

Select Port Forwarding.<br />

UDP<br />

The external service port that the FDN connects to. The external<br />

service port for push updates is usually 9443. If you changed the push<br />

update port in the FortiGuard Center configuration of the <strong>FortiGate</strong> unit<br />

on the internal network, you must set the external service port to the<br />

changed push update port.<br />

The map to port must be the same as the external service port.<br />

To add a firewall policy to the <strong>FortiGate</strong> NAT device<br />

1 Add a new external to internal firewall policy.<br />

2 Configure the policy with the following settings:<br />

3 Select OK.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

198 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!