12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

Virtual IPs<br />

Firewall Virtual IP<br />

This section describes <strong>FortiGate</strong> Virtual IPs and IP Pools and how to configure<br />

and use them in firewall policies.<br />

This section describes:<br />

• Virtual IPs<br />

• Viewing the virtual IP list<br />

• Configuring virtual IPs<br />

• Virtual IP Groups<br />

• Viewing the VIP group list<br />

• Configuring VIP groups<br />

• IP pools<br />

• Viewing the IP pool list<br />

• Configuring IP Pools<br />

• Double NAT: <strong>com</strong>bining IP pool with virtual IP<br />

Virtual IPs<br />

Virtual IPs can be used to allow connections through a <strong>FortiGate</strong> unit using<br />

network address translation (NAT) firewall policies. Virtual IPs use Proxy ARP so<br />

that the <strong>FortiGate</strong> unit can respond to ARP requests on a network for a server that<br />

is actually installed on another network. Proxy ARP is defined in RFC 1027.<br />

For example, you can add a virtual IP to an external <strong>FortiGate</strong> unit interface so<br />

that the external interface can respond to connection requests for users who are<br />

actually connecting to a server on the DMZ or internal network.<br />

How virtual IPs map connections through the <strong>FortiGate</strong> unit<br />

An example use of static NAT virtual IP is to allow easy public access to a web<br />

server on a private network protected by a <strong>FortiGate</strong> unit. Reduced to its basics,<br />

this example involves only three parts, as shown in Figure 191: the web server on<br />

a private network, the browsing <strong>com</strong>puter on the Internet, and the <strong>FortiGate</strong> unit<br />

connecting the two networks.<br />

A client <strong>com</strong>puter attempts to contact the server. The client <strong>com</strong>puter sends data<br />

packets and the <strong>FortiGate</strong> unit receives them. The addresses in the packets are<br />

remapped, and they’re forwarded to the server on the private network.<br />

Figure 191:A simple static NAT virtual IP example.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 305

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!