Search This Blog

Saturday, June 27, 2015

Fortigate port-forward using dynamic IP



Fortigate port-forwarding using dynamic IP (such as PPPoE and L2TP dialers).

Go to Policy & Objects -> Objects -> Virtual IPs and click Create New



Enter the VIP name

Choose the internal interface

Leave External IP Address/Range with all 0.0.0.0

Enter in Mapped IP Address/Range the internal IP address of the server

If you want all ports to forward to this address click OK else click Port Forwarding checkbox and enter the external and internal protocol and ports.

Here in my example its 192.168.10.150 (server IP) and I’ve mapped TCP port 80 to 33000.

Click OK

Go to Policy & Objects -> Policy -> IPv4 and click Create New



Choose WAN interface as incoming interface,

Choose LAN as outgoing interface,

Choose server VIP we have just created as Destination Address.

Select NAT on and select all other required parameters (AV, IPS, Web Filter etc.)

Click OK

That’s it.

9 comments:

  1. This is such a great resource that you are providing and you give it away for free. I love seeing blog that understand the value of providing a quality resource for free. Plus d'infos ici

    ReplyDelete
  2. Thank you for helping people get the information they need. Great stuff as usual. Keep up the great work!!! bezoek website

    ReplyDelete
  3. Very useful post. This is my first time i visit here. I found so many interesting stuff in your blog especially its discussion. Really its great article. Keep it up.  meer informatie

    ReplyDelete
  4. pleasant post, stay aware of this fascinating work. It truly regards realize that this subject is being secured likewise on this site so cheers for setting aside time to talk about this! privacyinthenetwork

    ReplyDelete
  5. The CSOne is web-based maintenance management software designed for maintenance and repair service providers. It is specifically designed to fulfill the requirements for these services and successfully improved productivity of thousands of users around the world privacyonline.com.br

    ReplyDelete
  6. I think this is an informative post and it is very beneficial and knowledgeable. Therefore, I would like to thank you for the endeavors that you have made in writing this article. All the content is absolutely well-researched. Thanks... https://192-168-i-i.com/

    ReplyDelete
  7. The equivalent is valid for all hardware on the web. Without this particular location, data can't be appropriately directed or gotten.ip address

    ReplyDelete
  8. While the topic of using proxy to overrule access control is a controversial point, you can use these proxies as long as your proxy server identifies and blocks proxies. find

    ReplyDelete
  9. Unfortunately, it is likely that your current email address list has a number of significant problems.my ip now

    ReplyDelete