12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

Configuring virtual IPs<br />

External Service Port<br />

Map Port<br />

The port traffic from the Internet will use. For a web server,<br />

this will typically be port 80.<br />

The port on which the server expects traffic. Since there is<br />

only one port, leave the second field blank.<br />

Figure 200:Virtual IP options; Static NAT port forwarding virtual IP for a single IP<br />

address and a single port<br />

4 Select OK.<br />

To add static NAT virtual IP port forwarding for a single IP address and a<br />

single port to a firewall policy<br />

Add a external to dmz1 firewall policy that uses the virtual IP so that when users<br />

on the Internet attempt to connect to the web server IP addresses, packets pass<br />

through the <strong>FortiGate</strong> unit from the external interface to the dmz1 interface. The<br />

virtual IP translates the destination addresses and ports of these packets from the<br />

external IP to the dmz network IP addresses of the web servers.<br />

1 Go to Firewall > Policy and select Create New.<br />

2 Configure the firewall policy:<br />

Source Interface/Zone external<br />

Source Address<br />

All (or a more specific address)<br />

Destination Interface/Zone dmz1<br />

Destination Address Port_fwd_NAT_VIP<br />

Schedule<br />

always<br />

Service<br />

HTTP<br />

Action<br />

ACCEPT<br />

3 Select NAT.<br />

4 Select OK.<br />

Adding static NAT port forwarding for an IP address range and a port range<br />

Ports 80 to 83 of addresses 192.168.37.4 to 192.168.37.7 on the Internet are<br />

mapped to ports 8000 to 8003 of addresses 10.10.10.42 to 10.10.10.44 on a<br />

private network. Attempts to <strong>com</strong>municate with 192.168.37.5, port 82 from the<br />

Internet, for example, are translated and sent to 10.10.10.43, port 8002 by the<br />

<strong>FortiGate</strong> unit. The <strong>com</strong>puters on the Internet are unaware of this translation and<br />

see a single <strong>com</strong>puter at 192.168.37.5 rather than a <strong>FortiGate</strong> unit with a private<br />

network behind it.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 315

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!