Skip to main content
Contributor III
October 18, 2007
Question

Forwarding TCP & UDP Ports

  • October 18, 2007
  • 9 replies
  • 6088 views
Hi there, I have just set up a 60B and am wanting to forward 1 UDP and 1 TCP port to a fixed IP address but I can' t find a straightforward way to do it! Any suggestions?

    9 replies

    rwpatterson
    New Member
    October 18, 2007
    Firewall -> Virtual IP. It' s pretty straight forward there. You could make 1 relationship with the entire IP address, or use two, one for each TCP/UDP port. After this create a policy that includes all VIPs and associated services with the source(s) and destination. That' s it.
    Contributor III
    October 22, 2007
    OK, Cheers Bob, as this is still not quite working I wanted to clarify - External Interface: WAN1 (ADSL) External IP: Public IP of ADSL? Internal IP: internal address of machine? This is about the only place I can see this not working as it seems v. simple. The port is still not forwarding properly though.
    Contributor III
    October 22, 2007
    My Apologies, the following tech doc sorted everything! http://kc.forticare.com/default.asp?SID=&Lang=1&id=2945
    rwpatterson
    New Member
    October 22, 2007
    Glad you have gotten it all sorted out. Enjoy.
    Contributor III
    November 13, 2007
    I have only one public IP address. Is it possible to have multiple internal websites published to the outside. Or even different ports on different machines with only one external IP?
    doshbass
    New Member
    November 13, 2007
    spamies, yes, you can use differnt ports to map to different internal IPs, although Ideally if its just websites you should host all sites on the same machine and use the HTTP host header string to differentiate the web sites
    Contributor III
    November 13, 2007
    ok I think I got it. Create virtual IPs for each port and destination ip. Do I need to also use services? And how do I map a port to the fortinet web admin page? I changed the port to 876 instead of 443 and mapped a port but it doesnt work.
    rwpatterson
    New Member
    November 13, 2007
    For the admin access, no policy or redirect is needed. Remove it, you should be good. You also need to enable at least the service you are redirecting TO. For example if you are hosting secure HTTP on port 12345 on the outside, the service must still be 443 on the policy, and the destination of the VIP mapping. You could use ' all' but you already know the single port you' re letting through. Tighten it up.
    Hracio
    New Member
    November 13, 2007
    I have only one public IP address. Is it possible to have multiple internal websites published to the outside. Or even different ports on different machines with only one external IP?
    This little tip should help: There are three types of virtual hosting. 1. IP Based Virtual Hosting (not commonly used) 2. Port Based Virtual Hosting (not commonly used) 3. Name Based Virtual Hosting (commonly used) Regards,. !
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!