Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Forwarding TCP & UDP Ports

Hi there, I have just set up a 60B and am wanting to forward 1 UDP and 1 TCP port to a fixed IP address but I can' t find a straightforward way to do it! Any suggestions?
9 REPLIES 9
rwpatterson
Valued Contributor III

Firewall -> Virtual IP. It' s pretty straight forward there. You could make 1 relationship with the entire IP address, or use two, one for each TCP/UDP port. After this create a policy that includes all VIPs and associated services with the source(s) and destination. That' s it.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

OK, Cheers Bob, as this is still not quite working I wanted to clarify - External Interface: WAN1 (ADSL) External IP: Public IP of ADSL? Internal IP: internal address of machine? This is about the only place I can see this not working as it seems v. simple. The port is still not forwarding properly though.
Not applicable

My Apologies, the following tech doc sorted everything! http://kc.forticare.com/default.asp?SID=&Lang=1&id=2945
rwpatterson
Valued Contributor III

Glad you have gotten it all sorted out. Enjoy.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

I have only one public IP address. Is it possible to have multiple internal websites published to the outside. Or even different ports on different machines with only one external IP?
doshbass
New Contributor III

spamies, yes, you can use differnt ports to map to different internal IPs, although Ideally if its just websites you should host all sites on the same machine and use the HTTP host header string to differentiate the web sites
Still learning to type " the"
Still learning to type " the"
Not applicable

ok I think I got it. Create virtual IPs for each port and destination ip. Do I need to also use services? And how do I map a port to the fortinet web admin page? I changed the port to 876 instead of 443 and mapped a port but it doesnt work.
rwpatterson
Valued Contributor III

For the admin access, no policy or redirect is needed. Remove it, you should be good. You also need to enable at least the service you are redirecting TO. For example if you are hosting secure HTTP on port 12345 on the outside, the service must still be 443 on the policy, and the destination of the VIP mapping. You could use ' all' but you already know the single port you' re letting through. Tighten it up.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Hracio
New Contributor

I have only one public IP address. Is it possible to have multiple internal websites published to the outside. Or even different ports on different machines with only one external IP?
This little tip should help: There are three types of virtual hosting. 1. IP Based Virtual Hosting (not commonly used) 2. Port Based Virtual Hosting (not commonly used) 3. Name Based Virtual Hosting (commonly used) Regards,. !
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors