Firewall Virtual IP
Configuring virtual IPs
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
375
•
To add a static NAT virtual IP with an IP address range to a firewall policy
Add a wan1 to dmz1 firewall policy that uses the virtual IP so that when users on the
Internet attempt to connect to the server IP addresses, packets pass through the
FortiGate unit from the wan1 interface to the dmz1 interface. The virtual IP translates the
destination addresses of these packets from the wan1 IP to the DMZ network IP
addresses of the servers.
1
Go to
Firewall > Policy
and select
Create New
.
2
Configure the firewall policy:
3
Select
NAT
.
4
Select
OK
.
Adding static NAT port forwarding for a single IP address and a single port
The IP address 192.168.37.4, port 80 on the Internet is mapped to 10.10.10.42, port 8000
on a private network. Attempts to communicate with 192.168.37.4, port 80 from the
Internet are translated and sent to 10.10.10.42, port 8000 by the FortiGate unit. The
computers on the Internet are unaware of this translation and see a single computer at
192.168.37.4, port 80 rather than a FortiGate unit with a private network behind it.
Figure 230: Static NAT virtual IP port forwarding for a single IP address and a single port
example
To add static NAT virtual IP port forwarding for a single IP address and a single port
1
Go to
Firewall > Virtual IP > Virtual IP
.
2
Select
Create New
.
Source Interface/Zone
wan1
Source Address
All (or a more specific address)
Destination
Interface/Zone
dmz1
Destination Address
static_NAT_range
Schedule
always
Service
HTTP
Action
ACCEPT
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...