Skip to main content
George
New Member
February 10, 2016
Solved

How to open a different port for a single IP address

  • February 10, 2016
  • 2 replies
  • 16047 views

Hi !

 

I have a Fortigate 90d model, and i have to open ports like 6080, 1433 and 1434. I wish that those ports to be open only to a single internal IP address

What should I do for make this simple task ?

    Best answer by ede_pfau

    Non-port forwarding VIPs and port-forwarding VIPs to the same destination address are mutually exclusive!

    Think of a non-port forwarding VIP as forwarding ALL ports, including the single port you already have defined in a port-forwarding VIP. Imagine traffic arriving for that destination port - which VIP should then respond?

    This is ambiguous and as such not allowed.

     

    @George:

    just define one VIP for each port you want to expose to the public interface (I'm assuming that is what you meant). To facilitate the policy, group those VIPs into a VIP group and use that as the destination address in the policy.

    Pretty straight forward and easy.

    2 replies

    nnBluestemfiber
    New Member
    February 10, 2016

    Create custom services using those ports

    Create a new policy Lan -> Lan

    Set Source and Destination as Node A and B

    Allow Services -- custom services created for those ports in the new policies

     

     

    neonbit
    New Member
    February 10, 2016

    Just to confirm, are you looking at these ports to be open for inbound traffic (ie internet hits those ports and it gets routed to single internal IP address) or outbound traffic (only single internal IP address is able to reach the internet on those ports)?

     

    For inbound traffic you will need to create a VIP, custom services and link them both in a policy (http://video.fortinet.com/video/116/port-forwarding-5-2)

     

    For outbound traffic follow nn's steps (policy needs to be LAN > WAN, Node A > Any)

    heedlix
    New Member
    February 13, 2016

    I'm trying to do the same thing for a FortiGate 30b.  Every time I try to create a VIP, I get a "A duplicate entry already exists" error, but the only entry in the VIP list has no port forwarding.

     

    Any ideas?

    Ali_FCNSP
    New Member
    February 14, 2016

    Under Object use Virtual IPs