12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring virtual IPs<br />

Firewall Virtual IP<br />

Figure 201:Static NAT virtual IP port forwarding for an IP address range and a port<br />

range example<br />

To add static NAT virtual IP port forwarding for an IP address range and a<br />

port range<br />

1 Go to Firewall > Virtual IP > Virtual IP.<br />

2 Select Create New.<br />

3 Use the following procedure to add a virtual IP that allows users on the Internet to<br />

connect to a web server on the DMZ network. In our example the external<br />

interface of the <strong>FortiGate</strong> unit is connected to the Internet and the dmz1 interface<br />

is connected to the DMZ network.<br />

Name<br />

Port_fwd_NAT_VIP_port_range<br />

External Interface external<br />

Type<br />

Static NAT<br />

External IP Address/Range The external IP addresses must be static IP addresses<br />

obtained from your ISP. This addresses must be unique, not<br />

used by another host, and cannot be the same as the IP<br />

address of the external interface the virtual IP will be using.<br />

However, the external IP addresses must be routed to the<br />

selected interface. The virtual IP addresses and the external<br />

IP address can be on different subnets. When you add the<br />

virtual IP, the external interface responds to ARP requests for<br />

the external IP addresses.<br />

Map to IP/IP Range The IP addresses of the server on the internal network.<br />

Define the range by entering the first address of the range in<br />

the first field and the last address of the range in the second<br />

field.<br />

Port Forwarding<br />

Selected<br />

Protocol<br />

TCP<br />

External Service Port The ports that traffic from the Internet will use. For a web<br />

server, this will typically be port 80.<br />

Map Port<br />

The ports on which the server expects traffic. Define the<br />

range by entering the first port of the range in the first field<br />

and the last port of the range in the second field. If there is<br />

only one port, leave the second field blank.<br />

4 Select OK.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

316 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!