12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

Configuring virtual IPs<br />

To add a server load balance virtual IP to a firewall policy<br />

Add a external to dmz1 firewall policy that uses the virtual IP so that when users<br />

on the Internet attempt to connect to the web server IP address packets pass<br />

through the <strong>FortiGate</strong> unit from the external interface to the dmz1 interface. The<br />

virtual IP translates the destination address of these packets from the external IP<br />

to the dmz network IP addresses of the web servers.<br />

1 Go to Firewall > Policy and select Create New.<br />

2 Configure the firewall policy:<br />

Source Interface/Zone external<br />

Source Address<br />

All (or a more specific address)<br />

Destination Interface/Zone dmz1<br />

Destination Address Server_Load_Bal_VIP<br />

Schedule<br />

always<br />

Service<br />

HTTP<br />

Action<br />

ACCEPT<br />

3 Select NAT.<br />

4 Select OK.<br />

Adding a server load balance port forwarding virtual IP<br />

In this example, connections to 192.168.37.4 on the Internet are mapped to<br />

10.10.10.42, 10.10.10.43, and 10.10.10.44 on a private network. The IP address<br />

mapping is determined by the <strong>FortiGate</strong> unit’s load balancing algorithm. The<br />

external service port on 192.168.37.4 is mapped to specified ports in conjunction<br />

with the specified IP addresses. The <strong>com</strong>puters on the Internet are unaware of<br />

this translation and see a single <strong>com</strong>puter at 192.168.37.4 rather than a <strong>FortiGate</strong><br />

unit with a private network behind it.<br />

Figure 204:Server load balance virtual IP port forwarding<br />

To add a server load balance port forwarding virtual IP<br />

1 Go to Firewall > Virtual IP > Virtual IP.<br />

2 Select Create New.<br />

3 Use the following procedure to add a virtual IP that allows users on the Internet to<br />

connect to a web server on the DMZ network. In our example the external<br />

interface of the <strong>FortiGate</strong> unit is connected to the Internet and the dmz1 interface<br />

is connected to the DMZ network.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 319

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!