Created on ‎10-27-2011 09:10 PM
get sys stat2. You are right in assuming that you need VIPs for port forwarding. If you get a ' duplicate address' error then you haven' t configured both VIPs for ' static NAT port forwarding' . You need to forward port 80 to port 80, and port 81 to port 81. You can specify the same source IP address (your WAN IP) and even the same internal IP address. But in your case the internal address will be .1 on the first VIP, and .2 on the second. Be aware that you will get a problem here. By default the Fortigate itself will listen on port 80 for HTTP requests to its WAN interface (or at least this could be enabled). Solve this conflict by moving the management port to any other ' high' port like 8080. You find that in System>Admin>Settings. 3. Security tips: narrow down the service you allow in the policy WAN->internal to the one you are forwarding. Port 80 translates into ' HTTP' (predefined service), port 81 is non-standard. You can define your own port81 custom service and specify that in the policy. Like with all port forwarding VIPs, your VIPs will not forward ICMP, i.e. ping! So don' t bother if your servers don' t respond to ping. 4. Get the FortiOS Handbook version 4.00 from http://docs.fortinet.com . Even if your firmware version is (a lot) older than that you will get the basics, examples and concepts of FortiOS. Without reading on the documentation you will have a hard time running this sophisticated firewall. HTH.
User | Count |
---|---|
2612 | |
1390 | |
804 | |
666 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.