12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Virtual IP Groups<br />

Firewall Virtual IP<br />

10 Enter the Map to Port number to be added to packets when they are forwarded.<br />

Enter the same number as the External Service Port if the port is not to be<br />

translated.<br />

11 Select OK.<br />

Adding a virtual IP with port translation only<br />

When adding a virtual IP, if you enter the virtual IP address as same as the<br />

mapped IP address and use port forwarding, the destination IP address will not be<br />

changed, but the port number will be changed as you specify.<br />

To add a virtual IP with port translation only<br />

1 Go to Firewall > Virtual IP > Virtual IP.<br />

2 Select Create New.<br />

3 Enter a name for the dynamic virtual IP.<br />

4 Select the virtual IP External Interface from the list.<br />

The external interface is connected to the source network and receives the<br />

packets to be forwarded to the destination network.<br />

Select any firewall interface or a VLAN subinterface.<br />

5 Set the External IP Address as the mapped IP address.<br />

6 Enter the Map to IP address to which to map the external IP address. For<br />

example, the IP address of a PPTP server on an internal network.<br />

7 Select Port Forwarding.<br />

8 For Protocol, select TCP.<br />

9 Enter the External Service Port number for which to configure dynamic port<br />

forwarding.<br />

The external service port number must match the destination port of the packets<br />

to be forwarded. For example, if the virtual IP provides PPTP passthrough access<br />

from the Internet to a PPTP server, the external service port number should be<br />

1723 (the PPTP port).<br />

10 Enter the Map to Port number to be added to packets when they are forwarded.<br />

11 Select OK.<br />

Virtual IP Groups<br />

You can create virtual IP groups to facilitate firewall policy traffic control. For<br />

example, on the DMZ interface, if you have two email servers that use Virtual IP<br />

mapping, you can put these two VIPs into one VIP group and create one externalto-DMZ<br />

policy, instead of two policies, to control the traffic.<br />

Viewing the VIP group list<br />

To view the virtual IP group list, go to Firewall > Virtual IP > VIP Group.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

322 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!