12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Double NAT: <strong>com</strong>bining IP pool with virtual IP<br />

Firewall Virtual IP<br />

To allow the local users to access the server, you can use fixed port and IP pool to<br />

allow more than one user connection while using virtual IP to translate the<br />

destination port from 8080 to 80.<br />

To create an IP pool<br />

1 Go to Firewall > Virtual IP > IP Pool.<br />

2 Select Create New.<br />

3 Enter the following information and select OK.<br />

Name<br />

pool-1<br />

Interface<br />

DMZ<br />

IP Range/Subnet 10.1.3.1-10.1.3.254<br />

To create a Virtual IP with port translation only<br />

1 Go to Firewall > Virtual IP > Virtual IP.<br />

2 Select Create New.<br />

3 Enter the following information and select OK.<br />

Name<br />

server-1<br />

External Interface Internal<br />

Type<br />

Static NAT<br />

External IP<br />

Address/Range<br />

172.16.1.1<br />

Note this address is the same as the server address.<br />

Mapped IP<br />

172.16.1.1.<br />

Address/Range<br />

Port Forwarding Enable<br />

Protocol<br />

TCP<br />

External Service Port 8080<br />

Map to Port 80<br />

To create a firewall policy<br />

Add an internal to dmz firewall policy that uses the virtual IP to translate the<br />

destination port number and the IP pool to translate the source addresses.<br />

1 Go to Firewall > Policy and select Create New.<br />

2 Configure the firewall policy:<br />

Source Interface/Zone internal<br />

Source Address 10.1.1.0/24<br />

Destination Interface/Zone dmz<br />

Destination Address<br />

server-1<br />

Schedule<br />

always<br />

Service<br />

HTTP<br />

Action<br />

ACCEPT<br />

3 Select NAT.<br />

4 Select OK.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

328 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!