12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

Virtual IPs<br />

If the NAT check box is not selected when building the firewall policy, the resulting<br />

policy will perform destination network address translation (DNAT). DNAT accepts<br />

packets from an external network that are intended for a specific destination IP<br />

address, translates the destination address of the packets to a mapped IP<br />

address on another hidden network, and then forwards the packets through the<br />

<strong>FortiGate</strong> unit to the hidden destination network. Unlike in the previous examples,<br />

the source address is not translated. Once on the hidden destination network, the<br />

packets can arrive at their final destination.<br />

Virtual IPs also translate the source IP address or addresses of return packets<br />

from the source address on the hidden network to be the same as the destination<br />

address of the originating packets.<br />

Virtual IP ranges can be of almost any size and can translate addresses to<br />

different subnets. Virtual IP ranges have the following restrictions:<br />

• The mapped IP cannot include 0.0.0.0 or 255.255.255.255.<br />

• The external IP cannot be 0.0.0.0 if the virtual IP type is static NAT and is<br />

mapped to a range of IP addresses. Only load balance virtual IPs, and<br />

static NAT virtual IPs mapped to a single IP address, support an external IP<br />

of 0.0.0.0.<br />

• Port mapping maps a range of external port numbers to a range of internal<br />

port numbers. The number of ports in these two ranges must be equal.<br />

Therefore, the external port must not be set so that its range exceeds<br />

65535. For example, an internal range of 20 ports mapped from external<br />

port 65530 is invalid as the last port in the range would be 65550.<br />

• When port forwarding, the external IP range cannot include any interface IP<br />

addresses.<br />

• The mapped IP range must not include any interface IP addresses.<br />

• Virtual IP name cannot be the same as any address name or address<br />

group name.<br />

• No duplicate entries or overlapping ranges are permitted.<br />

In addition to binding the IP address or IP address range to the interface, the<br />

virtual IP also contains all of the information required to map the IP address or IP<br />

address range from the interface that receives the packets to the interface<br />

connected to the same network as the actual IP address or IP address range.<br />

You can create different kinds of virtual IPs, each of which can be used for a<br />

different DNAT variation.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 307

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!