12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Firewall Virtual IP<br />

Configuring virtual IPs<br />

The virtual IP list has the following icons and features:<br />

Create New<br />

Name<br />

IP<br />

Service Port<br />

Map to IP/IP<br />

Range<br />

Map to Port<br />

Delete icon<br />

Edit icon<br />

Select to add a virtual IP.<br />

The name of the virtual IP.<br />

The external IP address or IP address range.<br />

The external port number or port number range. The service port is<br />

included in port forwarding virtual IPs.<br />

The mapped to IP address or address range on the destination network.<br />

The mapped to port number or port number range. The map to port is<br />

included in port forwarding virtual IPs.<br />

Remove the virtual IP from the list. The Delete icon only appears if the<br />

virtual IP is not being used in a firewall policy.<br />

Edit the virtual IP to change any virtual IP option including the virtual IP<br />

name.<br />

Configuring virtual IPs<br />

To add a virtual IP, go to Firewall > Virtual IP > Virtual IP and select Create new.<br />

To edit a virtual IP, go to Firewall > Virtual IP > Virtual IP and select the Edit icon<br />

for the virtual IP to edit.<br />

Name<br />

Enter or change the name to identify the virtual IP. To avoid confusion,<br />

firewall policies, addresses, address groups, and virtual IPs cannot<br />

share names.<br />

External Interface Select the virtual IP external interface from the list. The external<br />

interface is connected to the source network and receives the packets<br />

to be forwarded to the destination network. You can select any<br />

<strong>FortiGate</strong> interface, VLAN subinterface, or VPN interface.<br />

Type<br />

External IP<br />

Address/Range<br />

Mapped IP<br />

Address/Range<br />

Select Static NAT or Server Load Balance. For details about VIP<br />

types, see “How virtual IPs map connections through the <strong>FortiGate</strong><br />

unit” on page 305.<br />

Enter the external IP address that you want to map to an address on<br />

the destination network.<br />

To configure a dynamic virtual IP that accepts connections for any IP<br />

address, set the external IP address to 0.0.0.0. For a static NAT<br />

dynamic virtual IP you can only add one mapped IP address. For a<br />

load balance dynamic virtual IP you can specify a single mapped<br />

address or a mapped address range.<br />

Enter the real IP address on the destination network to which the<br />

external IP address is mapped.<br />

You can also enter an address range to forward packets to multiple IP<br />

addresses on the destination network.<br />

For a static NAT virtual IP, if you add a mapped IP address range the<br />

<strong>FortiGate</strong> unit calculates the external IP address range and adds the<br />

IP address range to the External IP Address/Range field.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 309

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!