Skip to main content
danfor443
New Member
July 8, 2020
Solved

How to use Virtual IP config

  • July 8, 2020
  • 4 replies
  • 7846 views

Hello Everyone

 

if i need my exchange-OWA accessable from Outside i need to create a Virtual IP.

eg my public IP is 123.123.123.123 and my internal Exchange IP is 192.168.1.1

 

So i want that 123.123.123.123 Port 443 maps to 192.168.1.1 Port 443.

 

And here is my question:

As far as i can see i have to possibilities to reach my goal.

 

*********************************************

Possibility 1) on VIP i configure

External IP Address/Range: 123.123.123.123

Mapped IP Address/Range: 192.168.1.1

 

On Port Forwarding i configure

External Service Port: 443

Map to Port: 443

*********************************************

 

 

 

*********************************************

Possibility 2) on VIP i configure

External IP Address/Range: 123.123.123.123

Mapped IP Address/Range: 192.168.1.1

And under "Optional Filters" i configure a Service like "HTTPS".

*********************************************

 

 

Both possibilities work.

Buth i guess there is something i don't understand?

 

Can you help me?

 

Best Regards,

Danfor

    Best answer by ede_pfau

    The filter is for narrowing down the allowed incoming traffic. A filter will not redirect traffic to other ports, but a port forwarding will.

    Sometimes, it is easier to allow some service and use a non-portforwarding VIP, than to configure several pVIPs.

    4 replies

    ede_pfau
    SuperUser
    ede_pfauAnswer
    SuperUser
    July 8, 2020

    The filter is for narrowing down the allowed incoming traffic. A filter will not redirect traffic to other ports, but a port forwarding will.

    Sometimes, it is easier to allow some service and use a non-portforwarding VIP, than to configure several pVIPs.

    danfor443
    danfor443Author
    New Member
    July 8, 2020

    Hi Ede,

     

    Aha! Nice to know, i didn't find that info in the handbook.

     

    Thank you very much.

    brycemd
    New Member
    July 8, 2020

    The filter can also be used to have multiple services on the same port, so long as it's possible to narrow it down.

     

    For example, if you have two external services that require a port forward on 443 to two different internal servers, you can use the VIP filter to narrow it down to the source public IP of the service. That way you can have two seemingly conflicting VIPs without the need to do port translation(or use a different public IP on your side).

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!