12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Virtual IP<br />

IP pools<br />

IP Pools for firewall policies that use fixed ports<br />

Some network configurations do not operate correctly if a NAT policy translates<br />

the source port of packets used by the connection. NAT translates source ports to<br />

keep track of connections for a particular service. Select fixed port for NAT<br />

policies to prevent source port translation. However, selecting fixed port means<br />

that only one connection can be supported through the firewall for this service. To<br />

be able to support multiple connections, add an IP pool to the destination<br />

interface, and then select dynamic IP pool in the policy. The firewall randomly<br />

selects an IP address from the IP pool and assigns it to each connection. In this<br />

case the number of connections that the firewall can support is limited by the<br />

number of IP addresses in the IP pool.<br />

Source IP address and IP pool address matching<br />

When the source addresses are translated to the IP pool addresses, one of the<br />

following three cases may occur:<br />

Scenario 1: The number of source addresses equals that of IP pool<br />

addresses<br />

In this case, the <strong>FortiGate</strong> unit will always match the IP addressed one to one.<br />

If you use fixed port in such a case, the <strong>FortiGate</strong> unit will preserve the original<br />

source port. However, this may cause conflicts if more than one firewall policy<br />

uses the same IP pool, or the same IP addresses are used in more than one IP<br />

pool.<br />

Original address<br />

Change to<br />

192.168.1.1 172.16.30.1<br />

192.168.1.2 172.16.30.2<br />

...... ......<br />

192.168.1.254 172.16.30.254<br />

Scenario 2: The number of source addresses is more than that of IP pool<br />

addresses<br />

In this case, the <strong>FortiGate</strong> unit translates IP addresses using a wrap-around<br />

mechanism.<br />

If you use fixed port in such a case, the <strong>FortiGate</strong> unit preserves the original<br />

source port. But conflicts may occur since users may have different sessions<br />

using the same TCP 5 tuples.<br />

Original address<br />

Change to<br />

192.168.1.1 172.16.30.10<br />

192.168.1.2 172.16.30.11<br />

...... ......<br />

192.168.1.10 172.16.30.19<br />

192.168.1.11 172.16.30.10<br />

192.168.1.12 172.16.30.11<br />

192.168.1.13 172.16.30.12<br />

...... ......<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 325

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!