12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Viewing the virtual IP list<br />

Firewall Virtual IP<br />

Static NAT<br />

Static NAT Port<br />

Forwarding<br />

Dynamic virtual<br />

IPs<br />

Server Load<br />

Balancing<br />

Server Load<br />

Balancing port<br />

forwarding<br />

Static NAT virtual IPs map an external IP address or IP address range<br />

on a source network to a mapped IP address or IP address range on a<br />

destination network.<br />

Static NAT virtual IPs use one-to-one mapping. A single external IP<br />

address is mapped to a single mapped IP address. A range of external<br />

IP addresses is mapped to a corresponding range of mapped IP<br />

addresses. A given IP address in the source address range is always<br />

mapped to the same IP address in the destination address range.<br />

Static NAT port forwarding maps a single IP address or address range<br />

and a single port number or port range on one network to a different<br />

single IP address or address range and a different single port number<br />

or port range on another network.<br />

Static NAT port forwarding is also just called port forwarding. Static NAT<br />

port forwarding virtual IPs use one-to-one mapping. A range of external<br />

IP addresses is mapped to a corresponding range of mapped IP<br />

addresses and a range of external port numbers is mapped to a<br />

corresponding range of mapped port numbers.<br />

Port forwarding virtual IPs can be used to configure the <strong>FortiGate</strong> unit<br />

for port address translation (PAT).<br />

If you set the external IP address of a virtual IP to 0.0.0.0, you create a<br />

dynamic virtual IP in which any external IP address is translated to the<br />

mapped IP address or IP address range.<br />

Server load balancing maps a single IP on one network to up to eight<br />

real server IPs on another network.<br />

At least one real address must be added to use this feature.<br />

Server load balancing with port forwarding maps a single IP address<br />

and port number on one network to up to eight specific server<br />

addresses and eight specific ports on another network.<br />

You must add the virtual IP to a NAT firewall policy to actually implement the<br />

mapping configured in the virtual IP. To add a firewall policy that maps addresses<br />

on an external network to an internal network, you add an external to internal<br />

firewall policy and add the virtual IP to the destination address field of the policy.<br />

For example, if the <strong>com</strong>puter hosting a web server is located on the internal<br />

network, it might have a private IP address such as 10.10.10.42. To get packets<br />

from the Internet to the web server, there must be an external address for the web<br />

server on the Internet. Add a virtual IP to the firewall that maps the external IP<br />

address of the web server on the Internet to the actual address of the web server<br />

on the internal network. To allow connections from the Internet to the web server,<br />

add an external to internal firewall policy and set the Destination Address to the<br />

virtual IP.<br />

Viewing the virtual IP list<br />

To view the virtual IP list, go to Firewall > Virtual IP > Virtual IP.<br />

Figure 194:Virtual IP list<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

308 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!