12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

Configuring virtual IPs<br />

3 Use the following procedure to add a virtual IP that allows users on the Internet to<br />

connect to three individual web servers on the DMZ network. In our example the<br />

external interface of the <strong>FortiGate</strong> unit is connected to the Internet and the dmz1<br />

interface is connected to the DMZ network.<br />

Name<br />

External Interface<br />

Type<br />

External IP<br />

Address/Range<br />

Map to IP/IP Range<br />

static_NAT_range<br />

external<br />

Static NAT<br />

The Internet IP address range of the web servers.<br />

The external IP addresses must be static IP addresses obtained<br />

from your ISP for your web server. These addresses must be<br />

unique IP addresses that are not used by another host and cannot<br />

be the same as the IP addresses of the external interface the<br />

virtual IP will be using. However, the external IP addresses must<br />

be routed to the selected interface. The virtual IP addresses and<br />

the external IP address can be on different subnets. When you<br />

add the virtual IP, the external interface responds to ARP requests<br />

for the external IP addresses.<br />

The IP address range of the servers on the internal network.<br />

Define the range by entering the first address of the range in the<br />

first field and the last address of the range in the second field.<br />

Figure 198:Virtual IP options; static NAT virtual IP with an IP address range<br />

4 Select OK.<br />

To add a static NAT virtual IP with an IP address range to a firewall policy<br />

Add a external to dmz1 firewall policy that uses the virtual IP so that when users<br />

on the Internet attempt to connect to the server IP addresses, packets pass<br />

through the <strong>FortiGate</strong> unit from the external interface to the dmz1 interface. The<br />

virtual IP translates the destination addresses of these packets from the external<br />

IP to the DMZ network IP addresses of the servers.<br />

1 Go to Firewall > Policy and select Create New.<br />

2 Configure the firewall policy:<br />

Source Interface/Zone external<br />

Source Address<br />

All (or a more specific address)<br />

Destination Interface/Zone dmz1<br />

Destination Address static_NAT_range<br />

Schedule<br />

always<br />

Service<br />

HTTP<br />

Action<br />

ACCEPT<br />

3 Select NAT.<br />

4 Select OK.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 313

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!