Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Forwarding 10 ports (both TCP and UDP) to one box using VIP' s

I have a Fortigate 60 with version 2.8 - build393,050405. Is there a way to forward a group of ports of both TCP and UDP (like all ports from 8000 - 8010 - TCP and UDP) without having to creat 20 different VIP' s and Policies? I can' t seem to figure out a way to do that so that it' s all handled by one VIP, and one firewall rule. I need to forward all of these ports through to one box in a DMZ and would think that there was an easier way. You can group services, but not VIP' s and then you need to have multiple policies - one for each VIP. This doesn' t make sense to me (unless I' m missing something - which is entirely possible, or I need to upgrade my firmware). Any help would be appreciated!! Thanks.
4 REPLIES 4
Not applicable

Well, yes... you can define a group of services and create one VIP fw the whole IP and define in the FW rule the group of services as the allowed traffic. Cheers Eric
Not applicable

I have some other port forwarding rules that forward port 80 and 443 to a webserver, 25 to an email server, etc. - and they are all on different boxes. If I try to map the whole IP to this new box, will that not take away all of the rest of my port forwarding, or if I put it last in the rule list, will only those ports that aren' t already redirected by previous rules be applied by the last rule? This is a frustrating limitation!! Does anyone know if there are plans to change this any time soon?
nsantin
New Contributor III

Keep in mind this only works if you can forward the whole IP. If you want to forward different ports to different destinations then you' re cooked. Here is the last discussion on this: http://support.fortinet.com/forum/tm.asp?m=9649&p=1&tmode=1&smode=1
nsantin
New Contributor III

You can' t create 2 VIP Ports for the same destination, so rule order is N/A. You could alwyas add them through the CLI, then it becomes cut&paste.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors