12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IP pools<br />

Firewall Virtual IP<br />

Group Name<br />

Interface<br />

Available VIPs and<br />

Members<br />

Enter or modify the group name.<br />

Select the interface for which you want to create the VIP<br />

group. If you are editing the group, the Interface box is<br />

grayed out.<br />

Add or remove members.<br />

IP pools<br />

IP pools and dynamic NAT<br />

Use IP pools to add NAT policies that translate source addresses to addresses<br />

randomly selected from the IP pool rather than being limited to the IP address of<br />

the destination interface.<br />

An IP pool defines an address or a range of IP addresses, all of which respond to<br />

ARP requests on the interface to which the IP pool is added.<br />

Select Enable Dynamic IP Pool in a firewall policy to translate the source address<br />

of outgoing packets to an address randomly selected from the IP pool. An IP pool<br />

list appears when the policy destination interface is the same as the IP pool<br />

interface.<br />

With an IP pool added to the internal interface, you can select Dynamic IP pool for<br />

policies with the internal interface as the destination.<br />

Add multiple IP pools to any interface and select the IP pool to use when<br />

configuring a firewall policy.<br />

A single IP address is entered normally. For example, 192.168.110.100 is a valid<br />

IP pool address. If an IP address range is required, use either of the following<br />

formats.<br />

• x.x.x.x-x.x.x.x, for example 192.168.110.100-192.168.110.120<br />

• x.x.x.[x-x], for example 192.168.110.[100-120]<br />

Use IP pools for dynamic NAT. For example, an organization might have<br />

purchased a range of Internet addresses but has only one Internet connection on<br />

the external interface of the <strong>FortiGate</strong> unit.<br />

Assign one of the organization’s Internet IP addresses to the external interface of<br />

the <strong>FortiGate</strong> unit. If the <strong>FortiGate</strong> unit is operating in NAT/Route mode, all<br />

connections from the network to the Internet appear to <strong>com</strong>e from this IP address.<br />

For connections to originate from all the Internet IP addresses, add this address<br />

range to an IP pool for the external interface. Then select Dynamic IP Pool for all<br />

policies with the external interface as the destination. For each connection, the<br />

firewall dynamically selects an IP address from the IP pool to be the source<br />

address for the connection. As a result, connections to the Internet appear to be<br />

originating from any of the IP addresses in the IP pool.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

324 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!