Skip to main content
tohritz
New Member
September 11, 2012
Question

Static Mapping to a Dynamic Public IP

  • September 11, 2012
  • 6 replies
  • 6065 views
Hope someone can enlighten me on this. Is there a way for a domain who has a dynamic IP to be statically mapped to an internal address? Lets say, I have example.example1.com domain and i want to create a static mapping to an internal ip address? I believe we can' t use the FQDN so what if the public ip of example.example1.com isn' t static? is this possible?

    6 replies

    Dave_Hall
    New Member
    September 11, 2012
    We use a 3rd party Dynamic DNS service for something similar (that is set up at one of the locations we manage) except the server in question is behind the Fortigate itself. If we are talking about a single server you may be better off setting up a port forward/mapping. If you need to set up a " domain" connection then perhaps setting up a VPN tunnel is ideal.
    ede_pfau
    SuperUser
    SuperUser
    September 12, 2012
    If you want to map an internal server (IP address) to your Fortigate' s external WAN IP which is changing dynamically then you can specify ' 0.0.0.0' as the external IP address in the VIP definition. The Fortigate will take this as ' whatever IP is currently assigned' .
    tohritz
    tohritzAuthor
    New Member
    September 14, 2012
    Just new to security and fortigate. Pardon for my questions, these may sound stupid.lol @Dave the server is behind the fortigate...When you' re referring to portforwarding, that' s setting up VIP then create a policy for wan>internal right? there' s no such thing as mapping FQDN to an internal ip right or there is? coz my problem is, the person i' m assisting doesn' t have a static ip for their domain. @ede I can' t use anymore my wan' s external IP. will this work for other wan ip but within my ip range?
    Dave_Hall
    New Member
    September 14, 2012
    ORIGINAL: tohritz @Dave the server is behind the fortigate...When you' re referring to portforwarding, that' s setting up VIP then create a policy for wan>internal right? there' s no such thing as mapping FQDN to an internal ip right or there is? coz my problem is, the person i' m assisting doesn' t have a static ip for their domain.
    Your problem is still a little vague -- what kind of access are you trying to grant this person to your internal network? There may be better solutions we can suggest. You can define a firewall object label as a FQDN, IP address, IP range. If your buddy can not set up his domain with a DDNS service (there are some cheap DDNS services you can get for under $20 per year), you can define a firewall object label that matches his IP/subnet range and use that for the firewall policy. Use this firewall object label for the " From address" field of the source (WAN) interface in the firewall policy. Re port forwarding -- although it' s not good security, you do not have to define a source IP to set up a port forwarding -- you can set the source to " all" and have it trigger on the port #. We have something like this set up for doing reverse VNC-connections (we run remote help desk software).
    ede_pfau
    SuperUser
    SuperUser
    September 14, 2012
    I was referring to the case of a dynamic WAN IP address. That would only be one (1), and with a VIP it would be ' used up' for that purpose. But, if you have several static WAN IPs which are routed to your FGT then you can use any of them for a VIP. Make sure that you define the interface IP address with the correct netmask to cover all of your external IP addresses.
    tohritz
    tohritzAuthor
    New Member
    September 23, 2012
    thanks for the replies guys. Can' t remember the exact details but this helps a lot. Just new to this so I might not be familiar with most of the topics but i' m slowly learning it.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!