Firewall
Virtual IP
FortiGate-3000 Administration Guide
01-28006-0010-20041105
225
You can now add the virtual IP to firewall policies.
To add port forwarding virtual IPs
1
Go to
Firewall > Virtual IP
.
2
Select Create New.
3
Enter a name for the port forwarding virtual IP.
4
Select the virtual IP External Interface from the list.
The external interface is connected to the source network and receives the packets to
be forwarded to the destination network.
You can select any firewall interface or a VLAN subinterface.
5
Select Port Forwarding.
6
Enter the External IP Address that you want to map to an address on the destination
interface.
You can set the external IP address to the IP address of the external interface
selected in step
4
or to any other address.
For example, if the virtual IP provides access from the Internet to a server on your
internal network, the external IP address must be a static IP address obtained from
your ISP for this server. This address must be a unique address that is not used by
another host. However, this address must be routed to the external interface selected
in step
4
. The virtual IP address and the external IP address can be on different
subnets.
7
Enter the External Service Port number for which you want to configure port
forwarding.
The external service port number must match the destination port of the packets to be
forwarded. For example, if the virtual IP provides access from the Internet to a web
server, the external service port number is 80 (the HTTP port).
8
Enter the Map to IP address to which to map the external IP address. For example,
the IP address of a web server on an internal network.
9
Enter the Map to Port number to be added to packets when they are forwarded.
If you do not want to translate the port, enter the same number as the External Service
Port.
10
Select OK.
Table 22: Virtual IP external interface examples
External Interface Description
internal
To map an internal address to an address on a network connected to
another interface, VLAN subinterface, or zone. If you select internal, the
static NAT virtual IP can be added to policies for connections from the
internal interface or any zone containing the internal interface, to any
other interface, VLAN subinterface, or zone.
external
To map an external address to an address on a network connected to
another interface, VLAN subinterface, or zone. If you select external, the
static NAT virtual IP can be added to policies for connections from the
external interface or any zone containing the external interface, to any
other interface, VLAN subinterface, or zone.
Summary of Contents for FortiGate 3000
Page 18: ...Contents 18 01 28006 0010 20041105 Fortinet Inc ...
Page 52: ...52 01 28006 0010 20041105 Fortinet Inc Changing the FortiGate firmware System status ...
Page 78: ...78 01 28006 0010 20041105 Fortinet Inc FortiGate IPv6 support System network ...
Page 86: ...86 01 28006 0010 20041105 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28006 0010 20041105 Fortinet Inc FortiManager System config ...
Page 122: ...122 01 28006 0010 20041105 Fortinet Inc Access profiles System administration ...
Page 252: ...252 01 28006 0010 20041105 Fortinet Inc CLI configuration Users and authentication ...
Page 390: ...390 01 28006 0010 20041105 Fortinet Inc Glossary ...
Page 398: ...398 01 28006 0010 20041105 Fortinet Inc Index ...