12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

Configuring virtual IPs<br />

To add static NAT virtual IP port forwarding for an IP address range and a<br />

port range to a firewall policy<br />

Add a external to dmz1 firewall policy that uses the virtual IP so that when users<br />

on the Internet attempt to connect to the web server IP addresses, packets pass<br />

through the <strong>FortiGate</strong> unit from the external interface to the dmz1 interface. The<br />

virtual IP translates the destination addresses and ports of these packets from the<br />

external IP to the dmz network IP addresses of the web servers.<br />

1 Go to Firewall > Policy and select Create New.<br />

2 Configure the firewall policy:<br />

Source Interface/Zone external<br />

Source Address<br />

All (or a more specific address)<br />

Destination Interface/Zone dmz1<br />

Destination Address Port_fwd_NAT_VIP_port_range<br />

Schedule<br />

always<br />

Service<br />

HTTP<br />

Action<br />

ACCEPT<br />

3 Select NAT.<br />

4 Select OK.<br />

Adding a server load balance virtual IP<br />

In this example the IP address 192.168.37.4 on the Internet, is mapped to the<br />

following servers behind the fortiGate unit, 10.10.123.42, 10.10.123.43, and<br />

10.10.123.44. The IP address mapping is determined by the <strong>FortiGate</strong> unit’s load<br />

balancing algorithm. Attempts to <strong>com</strong>municate with 192.168.37.4 from the<br />

Internet are translated and sent to 10.10.10.42, 10.10.10.43, or 10.10.10.44 by<br />

the <strong>FortiGate</strong> unit. The <strong>com</strong>puters on the Internet are unaware of this translation<br />

and see a single <strong>com</strong>puter at 192.168.37.4 rather than a <strong>FortiGate</strong> unit with a<br />

private network behind it.<br />

Note: Server load balancing maps a single IP on one network to up to eight real server IPs<br />

on another network. At least one real address must be added to use this feature<br />

Figure 202:Server Load balance virtual IP<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 317

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!