How do I configure a Virtual IP

About virtual IPs

Virtual IP (VIP) addresses enable users from outside a private network to access services inside that network. Under normal circumstances, this is not possible because Internet routers generally do not connect to private IP addresses. For example, a user from the Internet is not able to access an internal page on a company network. However, the FortiGate unit can be configured to allow an employee of a company to access an internal web page on a private network from the Internet.

 

FortiGate must be in NAT/Route mode to add VIPs.

Creating a static VIP

Static NAT virtual IP for a single IP address is the simplest virtual IP configuration. A single IP address on one network is mapped to another IP address on a second network. The FortiGate unit connects the two networks and allows communication between them.

To create a static VIP

  1. Go to Firewall > Virtual IP.
  2. Select Create New.
  3. Enter a name for the Virtual IP you will create.
  4. Select the interface the new Virtual IP will be entering from.
  5. Select Static NAT.
  6. Enter the address for the virtual IP in External IP Address/Range.
    This is the address visible to users outside the network.
  7. Enter the internal IP address in Map to IP Address/Range.
    This address is invisible to users outside the network. It is the address for the page linked to the external IP.
  8. Select OK

Creating a VIP with port forwarding

With port forwarding, a port or a range of ports on computers outside the network can be linked to a port or range of ports inside the network.

To create a VIP with port forwarding

  1. Go to Firewall > Virtual IP.
  2. Select Create New.
  3. Enter a name for the Virtual IP you will create.
  4. Select the interface the new Virtual IP will be entering from.
  5. Select Port Forwarding.
  6. Enter the address for the virtual IP in External IP Address/Range.
    This is the address visible to users outside the network.
  7. Enter the internal IP address in Map to IP Address/Range.
    This address is invisible to users outside the network. It is the address for the page linked to the external IP.
  8. Select OK

Configuring the Firewall

You must create a firewall service and a firewall policy for the Virtual IP address to function, and to allow traffic to flow between the VIP and the network.

To create a firewall service

  1. Go to Firewall > Service > Custom.
  2. Select Create New
  3. Enter a name for the new service.
  4. Select the protocol for the new VIP.
  5. Leave the default settings for Source Port.
  6. Enter the destination port numbers for the new service.
  7. Select OK.

To create a firewall policy

  1. Go to Firewall > Policy.
  2. Select Create New
  3. Select the external port connected to the internet for Source Interface/Zone.
  4. Select all for Source Address Name.
  5. Select the internal port connected to the network for Destination Interface/Zone.
  6. Select the virtual IP you created for Destination Address Name.
  7. Select the service you just created from the Service options.
  8. Select OK.

  

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值