Hello, I am trying to convert incoming port 22 to 2222 with a VIP rule. However I want to keep the same external and internal IP address. The VIP will not accept this.
Is there any way to only convert incoming ports with the same address ?
Hey @douglas1942,
you can check this KB: https://community.fortinet.com/t5/No-tags-TKBs/Technical-Tip-how-to-set-port-translation-port-forwar...
Is that what you're looking for?
Cheers!
Hello @douglas1942
It sounds like you're trying to set up port forwarding using a VIP but you want to maintain the same external and internal IP addresses.
If your VIP doesn't allow you to change the port number while keeping the same IP address, Instead of changing the incoming port, consider using a different external port for SSH altogether (e.g., port 2222) and leave the internal port at 22. This way, you won't need to perform any port translation.
Remember that whenever you make changes to your network configuration, especially involving port forwarding and SSH, test the behavior in closed environment. Let us know if you have any queries.
Thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1767 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.