Virtual IPs to forward services on internal segmentation firewall
Hi!
I want to replace my old Linux UTM-box that is working as internal segmentation firewall with a Fortigate system. As the system is providing some services
At the moment, the system is forwarding incoming traffic to other system with DNAT-rules, e.g.:
Incoming NTP-Sessions on 10.10.10.1 forward to NTP-Server 10.20.20.20
Incoming DNS-Sessions to AD-Controller-Server
Incoming SMTP-Sessions to Postfix-Server
Incoming Squid-Sessions to Squid-Server
As I do not want to change the configuration of many clients, how can I configure this?
What I tried (without success):
- Add IPv4 Virtual IP: External IP 10.10.10.1 (which is the IP of the Fortigate AND default gateway of the clients), Mapped IP 172.10.10.10, TCP 3128
- Add IPv4 Policy Allow any,any (for testing only)
What did I forget?
I think, I need a Local In Policy, but I do not find any hint on how to do that
Can you give me a hint?
Thank you and best wishes,
KPS
