Dest Port Forwarding with preserve Dest Ip
Hello,
I have been digging all the web, the Online Fortihelp, even the FortiSupport seems to be lost about this simple thing i need :
Translating the Destination Port without Translating the Source or Destination IP Address !
Exemple :
TCP-22 --> TCP-2222 For any source IP and 1.1.1.1 dest IP :
Int in : 192.168.1.1 --> 1.1.1.1:22
Int out : 192.168.1.1 --> 1.1.1.1:2222
That's all...
Everyone (really everyone) on internet whose approach the research subject of Port Forwading :
" Yes very simple : Virtual IP ! You set your port forwarding with Mapping your IP to another..."
I do not want this... I want to Dest Port Forwarding and preserve the dest Ip.
Ofcourse, Fortinet doesn't allow me to do this :
Ext Ip Range : 1.1.1.1 - 1.1.1.1
Mapped IP : 1.1.1.1
Or even this (make me getting out with IP 0.0.0.0):
Ext Ip Range : 1.1.1.1 - 1.1.1.1
Mapped IP : 0.0.0.0
I have tried this (FortiGate accept...)
Ext Ip Range : 0.0.0.0 - 0.0.0.0 (Though was an "any"...)
Mapped IP :1.1.1.1
but my VIP doesn't get matched into policy... The Policy seems to wait fort an dest IP 0.0.0.0 (
)
Support told me to active Central Nat ... well, i don't want to fixe the source Port... That's not what i need..
I mean... it's not a pb for all other competitor's product i have been working with .. Cisco ASA, Checkpoint, Juniper...
They all offer an simple way to make a DNAT Port without touching the IP@ part...
Please, tell me i'm just missing the Fortigate trick for this need... i can't believe that i'm the only one ..
Thanks for reading.
Fortigate 100E v6.0.4 -0231
