12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

Configuring virtual IPs<br />

To add a server load balance virtual IP to a firewall policy<br />

Add a external to dmz1 firewall policy that uses the virtual IP so that when users<br />

on the Internet attempt to connect to the web server IP address packets pass<br />

through the <strong>FortiGate</strong> unit from the external interface to the dmz1 interface. The<br />

virtual IP translates the destination address of these packets from the external IP<br />

to the dmz network IP addresses of the web servers.<br />

1 Go to Firewall > Policy and select Create New.<br />

2 Configure the firewall policy:<br />

3 Select NAT.<br />

4 Select OK.<br />

Adding dynamic virtual IPs<br />

Source Interface/Zone external<br />

Source Address<br />

All (or a more specific address)<br />

Destination Interface/Zone dmz1<br />

Destination Address Load_Bal_VIP_port_forward<br />

Schedule<br />

always<br />

Service<br />

HTTP<br />

Action<br />

ACCEPT<br />

Adding a dynamic virtual IP is similar to adding a virtual IP. The difference is that<br />

the External IP address must be set to 0.0.0.0 so the External IP address matches<br />

any IP address.<br />

To add a dynamic virtual IP<br />

1 Go to Firewall > Virtual IP > Virtual IP.<br />

2 Select Create New.<br />

3 Enter a name for the dynamic virtual IP.<br />

4 Select the virtual IP External Interface from the list.<br />

The external interface is connected to the source network and receives the<br />

packets to be forwarded to the destination network.<br />

Select any firewall interface or a VLAN subinterface.<br />

5 Set the External IP Address to 0.0.0.0.<br />

The 0.0.0.0 External IP Address matches any IP address.<br />

6 Enter the Map to IP address to which to map the external IP address. For<br />

example, the IP address of a PPTP server on an internal network.<br />

7 Select Port Forwarding.<br />

8 For Protocol, select TCP.<br />

9 Enter the External Service Port number for which to configure dynamic port<br />

forwarding.<br />

The external service port number must match the destination port of the packets<br />

to be forwarded. For example, if the virtual IP provides PPTP passthrough access<br />

from the Internet to a PPTP server, the external service port number should be<br />

1723 (the PPTP port).<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 321

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!