12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring virtual IPs<br />

Firewall Virtual IP<br />

To add a static NAT virtual IP for a single IP address to a firewall policy<br />

Add a external to dmz1 firewall policy that uses the virtual IP so that when users<br />

on the Internet attempt to connect to the web server IP address packets pass<br />

through the <strong>FortiGate</strong> unit from the external interface to the dmz1 interface. The<br />

virtual IP translates the destination address of these packets from the external IP<br />

to the DMZ network IP address of the web server.<br />

1 Go to Firewall > Policy and select Create New.<br />

2 Configure the firewall policy:<br />

Source Interface/Zone external<br />

Source Address<br />

All (or a more specific address)<br />

Destination Interface/Zone dmz1<br />

Destination Address simple_static_nat<br />

Schedule<br />

always<br />

Service<br />

HTTP<br />

Action<br />

ACCEPT<br />

3 Select NAT.<br />

4 Select OK.<br />

Adding a static NAT virtual IP for an IP address range<br />

The IP address range 192.168.37.4-192.168.37.6 on the Internet is mapped to<br />

10.10.10.42-10.10.123.44 on a private network. Packets from Internet <strong>com</strong>puters<br />

<strong>com</strong>municating with 192.168.37.4 are translated and sent to 10.10.10.42 by the<br />

<strong>FortiGate</strong> unit. Similarly, packets destined for 192.168.37.5 are translated and<br />

sent to 10.10.10.43, and packets destined for 192.168.37.6 are translated and<br />

sent to 10.10.10.44. The <strong>com</strong>puters on the Internet are unaware of this translation<br />

and see three <strong>com</strong>puters with individual IP addresses rather than a <strong>FortiGate</strong> unit<br />

with a private network behind it.<br />

Figure 197:Static NAT virtual IP for an IP address range example<br />

To add a static NAT virtual IP for an IP address range<br />

1 Go to Firewall > Virtual IP > Virtual IP.<br />

2 Select Create New.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

312 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!