12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

Configuring virtual IPs<br />

Figure 195:Static NAT virtual IP for a single IP address example<br />

To add a static NAT virtual IP for a single IP address<br />

1 Go to Firewall > Virtual IP > Virtual IP.<br />

2 Select Create New.<br />

3 Use the following procedure to add a virtual IP that allows users on the Internet to<br />

connect to a web server on the DMZ network. In our example the external<br />

interface of the <strong>FortiGate</strong> unit is connected to the Internet and the dmz1 interface<br />

is connected to the DMZ network.<br />

Name<br />

simple_static_NAT<br />

External Interface external<br />

Type<br />

Static NAT<br />

External IP<br />

Address/Range<br />

The Internet IP address of the web server.<br />

The external IP address must be a static IP address obtained from<br />

your ISP for your web server. This address must be a unique IP<br />

address that is not used by another host and cannot be the same as<br />

the IP address of the external interface the virtual IP will be using.<br />

However, the external IP address must be routed to the selected<br />

interface. The virtual IP address and the external IP address can be<br />

on different subnets. When you add the virtual IP, the external<br />

interface responds to ARP requests for the external IP address.<br />

Map to IP/IP Range The IP address of the server on the internal network. Since there is<br />

only one IP address, leave the second field blank.<br />

Figure 196:Virtual IP options: static NAT virtual IP for a single IP address<br />

4 Select OK.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 311

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!