Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tohritz
New Contributor

Static Mapping to a Dynamic Public IP

Hope someone can enlighten me on this. Is there a way for a domain who has a dynamic IP to be statically mapped to an internal address? Lets say, I have example.example1.com domain and i want to create a static mapping to an internal ip address? I believe we can' t use the FQDN so what if the public ip of example.example1.com isn' t static? is this possible?
tohritz
tohritz
6 REPLIES 6
Dave_Hall
Honored Contributor

We use a 3rd party Dynamic DNS service for something similar (that is set up at one of the locations we manage) except the server in question is behind the Fortigate itself. If we are talking about a single server you may be better off setting up a port forward/mapping. If you need to set up a " domain" connection then perhaps setting up a VPN tunnel is ideal.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ede_pfau
SuperUser
SuperUser

If you want to map an internal server (IP address) to your Fortigate' s external WAN IP which is changing dynamically then you can specify ' 0.0.0.0' as the external IP address in the VIP definition. The Fortigate will take this as ' whatever IP is currently assigned' .
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
tohritz
New Contributor

Just new to security and fortigate. Pardon for my questions, these may sound stupid.lol @Dave the server is behind the fortigate...When you' re referring to portforwarding, that' s setting up VIP then create a policy for wan>internal right? there' s no such thing as mapping FQDN to an internal ip right or there is? coz my problem is, the person i' m assisting doesn' t have a static ip for their domain. @ede I can' t use anymore my wan' s external IP. will this work for other wan ip but within my ip range?
tohritz
tohritz
Dave_Hall
Honored Contributor

ORIGINAL: tohritz @Dave the server is behind the fortigate...When you' re referring to portforwarding, that' s setting up VIP then create a policy for wan>internal right? there' s no such thing as mapping FQDN to an internal ip right or there is? coz my problem is, the person i' m assisting doesn' t have a static ip for their domain.
Your problem is still a little vague -- what kind of access are you trying to grant this person to your internal network? There may be better solutions we can suggest. You can define a firewall object label as a FQDN, IP address, IP range. If your buddy can not set up his domain with a DDNS service (there are some cheap DDNS services you can get for under $20 per year), you can define a firewall object label that matches his IP/subnet range and use that for the firewall policy. Use this firewall object label for the " From address" field of the source (WAN) interface in the firewall policy. Re port forwarding -- although it' s not good security, you do not have to define a source IP to set up a port forwarding -- you can set the source to " all" and have it trigger on the port #. We have something like this set up for doing reverse VNC-connections (we run remote help desk software).

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ede_pfau
SuperUser
SuperUser

I was referring to the case of a dynamic WAN IP address. That would only be one (1), and with a VIP it would be ' used up' for that purpose. But, if you have several static WAN IPs which are routed to your FGT then you can use any of them for a VIP. Make sure that you define the interface IP address with the correct netmask to cover all of your external IP addresses.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
tohritz
New Contributor

thanks for the replies guys. Can' t remember the exact details but this helps a lot. Just new to this so I might not be familiar with most of the topics but i' m slowly learning it.
tohritz
tohritz
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors