12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Firewall Virtual IP<br />

Configuring IP Pools<br />

Configuring IP Pools<br />

To add an IP pool, go to Firewall > Virtual IP > IP Pool.<br />

Figure 209:New Dynamic IP Pool<br />

Name<br />

Enter or change the name for the IP pool.<br />

Interface Select the interface to which to add an IP pool.<br />

IP Range/Subnet Enter the IP address range for the IP pool. The IP range defines the<br />

start and end of an address range. The start of the range must be lower<br />

than the end of the range. The IP range does not have to be on the<br />

same subnet as the IP address of the interface to which the IP pool is<br />

being added.<br />

Double NAT: <strong>com</strong>bining IP pool with virtual IP<br />

When creating a firewall policy, you can use both IP pool and virtual IP for double<br />

IP and/or port translation.<br />

For example, in the following network topology:<br />

• Users in the 10.1.1.0/24 subnet use port 8080 to access server 172.16.1.1.<br />

• The server’s listening port is 80.<br />

• Fixed ports must be used.<br />

Figure 210:Double NAT<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 327

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!