Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Antti
New Contributor

Port forwarding from IP-range to single IP

Hi,

 

I'm quite new to the world of FortiGate.

 

I need to forward traffic from IP-range to specific ports of certain device.

(Everything from IP 123.123.123.XXX --> 192.192.192.123 TCP 111, 222 and UDP 111, 222)

 

What is the best way to do this? At the first glance with the VIPs I would be have to make four digit number of rules.

The firewall in use is FortiGate 60E

 

-Antti

 

 

13 REPLIES 13
GusTech
Contributor II

Ok, setup: External IP address/Range 0.0.0.0 - 0.0.0.0 Mapped IP Address/Range machine - machine   Create a policy from external to your machine interface that control access 

Fortigate <3

Fortigate <3
GusTech

I do not know setup of your external network, this will only work if trafic hits fortigate 

 

Fortigate <3

Fortigate <3
GusTech

I do not know setup of your complete network, this will only work if trafic hits fortigate 

Fortigate <3

Fortigate <3
ede_pfau

I think @Antti has the right idea to employ a source address filter in the VIP definition. This requires a newer FortiOS (v5.4+ ?).

The difference between source IP filter and source IP address object in the access policy is that in the first case the VIP will only be active for the source address range specified (think of arp replies) whereas with filtering in the policy the VIP will trigger for any source address, and block the inappropriate ones. This could easily lead to a 'black hole' sucking up all traffic on ports 111 and 222.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors