Hello Everyone
if i need my exchange-OWA accessable from Outside i need to create a Virtual IP.
eg my public IP is 123.123.123.123 and my internal Exchange IP is 192.168.1.1
So i want that 123.123.123.123 Port 443 maps to 192.168.1.1 Port 443.
And here is my question:
As far as i can see i have to possibilities to reach my goal.
*********************************************
Possibility 1) on VIP i configure
External IP Address/Range: 123.123.123.123
Mapped IP Address/Range: 192.168.1.1
On Port Forwarding i configure
External Service Port: 443
Map to Port: 443
*********************************************
*********************************************
Possibility 2) on VIP i configure
External IP Address/Range: 123.123.123.123
Mapped IP Address/Range: 192.168.1.1
And under "Optional Filters" i configure a Service like "HTTPS".
*********************************************
Both possibilities work.
Buth i guess there is something i don't understand?
Can you help me?
Best Regards,
Danfor
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The filter is for narrowing down the allowed incoming traffic. A filter will not redirect traffic to other ports, but a port forwarding will.
Sometimes, it is easier to allow some service and use a non-portforwarding VIP, than to configure several pVIPs.
The filter is for narrowing down the allowed incoming traffic. A filter will not redirect traffic to other ports, but a port forwarding will.
Sometimes, it is easier to allow some service and use a non-portforwarding VIP, than to configure several pVIPs.
Hi Ede,
Aha! Nice to know, i didn't find that info in the handbook.
Thank you very much.
The filter can also be used to have multiple services on the same port, so long as it's possible to narrow it down.
For example, if you have two external services that require a port forward on 443 to two different internal servers, you can use the VIP filter to narrow it down to the source public IP of the service. That way you can have two seemingly conflicting VIPs without the need to do port translation(or use a different public IP on your side).
I don't recommend using port-forwarding VIP unless absolutely necessary. I have none in production, as my public servers have a 1-to-1 mapping. Firewall policy is where only port 443 (HTTPS) is allowed. No reason to complicate things unless you need multiple servers to listen on the same IP (something I know happens often enough for some folks).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.