12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring virtual IPs<br />

Firewall Virtual IP<br />

Adding static NAT port forwarding for a single IP address and a single port<br />

The IP address 192.168.37.4, port 80 on the Internet is mapped to 10.10.10.42,<br />

port 8000 on a private network. Attempts to <strong>com</strong>municate with 192.168.37.4,<br />

port 80 from the Internet are translated and sent to 10.10.10.42, port 8000 by the<br />

<strong>FortiGate</strong> unit. The <strong>com</strong>puters on the Internet are unaware of this translation and<br />

see a single <strong>com</strong>puter at 192.168.37.4, port 80 rather than a <strong>FortiGate</strong> unit with a<br />

private network behind it.<br />

Figure 199:Static NAT virtual IP port forwarding for a single IP address and a single<br />

port example<br />

To add static NAT virtual IP port forwarding for a single IP address and a<br />

single port<br />

1 Go to Firewall > Virtual IP > Virtual IP.<br />

2 Select Create New.<br />

3 Use the following procedure to add a virtual IP that allows users on the Internet to<br />

connect to a web server on the DMZ network. In our example the external<br />

interface of the <strong>FortiGate</strong> unit is connected to the Internet and the dmz1 interface<br />

is connected to the DMZ network.<br />

Name<br />

Port_fwd_NAT_VIP<br />

External Interface external<br />

Type<br />

Static NAT<br />

External IP Address/Range The Internet IP address of the web server.<br />

The external IP address must be a static IP address obtained<br />

from your ISP for your web server. This address must be a<br />

unique IP address that is not used by another host and<br />

cannot be the same as the IP address of the external<br />

interface the virtual IP will be using. However, the external IP<br />

address must be routed to the selected interface. The virtual<br />

IP address and the external IP address can be on different<br />

subnets. When you add the virtual IP, the external interface<br />

responds to ARP requests for the external IP address.<br />

Map to IP/IP Range The IP address of the server on the internal network. Since<br />

there is only one IP address, leave the second field blank.<br />

Port Forwarding<br />

Selected<br />

Protocol<br />

TCP<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

314 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!