12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring virtual IPs<br />

Firewall Virtual IP<br />

Method<br />

Port forwarding<br />

Protocol<br />

External Service<br />

Port<br />

Map to Port<br />

Real Servers<br />

If you select Server Load Balance, you can select one of the following<br />

load balancing methods.<br />

• Static: The traffic load is spread evenly across all servers, no<br />

additional server is required.<br />

• Round Robin: Directs request to the next server, and treats all<br />

servers as equals regardless of response time or number of<br />

connections. Dead servers or non responsive servers are avoided.<br />

A separate server is required.<br />

• Weighted: Servers with a higher weight value will receive a larger<br />

percentage of connections. Set the server weight when adding a<br />

server.<br />

Select to add a port forwarding virtual IP.<br />

Select the protocol (TCP or UDP) that you want the forwarded packets<br />

to use.<br />

Enter the external service port number for which you want to configure<br />

port forwarding.<br />

Enter the port number on the destination network to which the<br />

external port number is mapped.<br />

You can also enter a port number range to forward packets to multiple<br />

ports on the destination network.<br />

For a static NAT virtual IP, if you add a map to port range the <strong>FortiGate</strong><br />

unit calculates the external port number range and adds the port<br />

number range to the External Service port field.<br />

If you select Server Load Balancing for the VIP type, enter the real<br />

server IP addresses. At least one IP address is required and you can<br />

enter up to eight addresses.<br />

To enter a server IP address, select Add under Real Servers and<br />

enter the following information:<br />

IP: Enter the IP address of the server.<br />

Port: If you enable port forwarding, enter the port number on the<br />

destination network to which the external port number is mapped.<br />

Dead interval: The interval of time that a connection can remain idle<br />

before it is dropped. A range of 10-255 seconds can be used.<br />

Wake interval: The interval of time the connection will try to detect a<br />

server before giving up. A range of 10-255 seconds can be used.<br />

Weight: Determines the weight value of a specific server. The high<br />

the weight value, the higher the percentage of connections the server<br />

will handle. A range of 1-255 can be used.<br />

Health Check: Enable this option to use ping detection to check the<br />

status of the server before forwarding the session.<br />

Adding a static NAT virtual IP for a single IP address<br />

The IP address 192.168.37.4 on the Internet is mapped to 10.10.10.42 on a<br />

private network. Attempts to <strong>com</strong>municate with 192.168.37.4 from the Internet are<br />

translated and sent to 10.10.10.42 by the <strong>FortiGate</strong> unit. The <strong>com</strong>puters on the<br />

Internet are unaware of this translation and see a single <strong>com</strong>puter at 192.168.37.4<br />

rather than a <strong>FortiGate</strong> unit with a private network behind it.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

310 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!