Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Virtual IP limitation?

I need to get our new Fortigate 60B up and running this weekend. I' m not sure if Fortinet' s email support is running, so am posting here, too. I work for a small company, and we are currently using just one public IP address, mapped to multiple internal servers on our 192.168.2.0 network, using a " toy" Watchguard box. It looks something like this <public ip>:21 -> Server 2:21 <public ip>:25 -> Server 1:25 <public ip>:80 -> Server 2:80 <public ip>:81 -> Server 3:81 <public ip>:110 -> Server 1:110 <public ip>:443 -> Server 2:443 <public ip>:444 -> Server 3:444 I can' t seem to recreate this setup with Virtual IP' s. Until I realized that Virtual IP' s were necessary to enable NAT (correct?), it all looked so easy by adding each server under Firewall -> Address. Then I created Firewall Policies for WAN1 -> Internal, mapping each service to the appropriate Destination Address. But it didn' t work. With a Virtual IP it works fine, but it seems I can only map the public IP to ONE internal server. That is, I can send services to just ONE server, not to three. I hope I' m missing something simple, or else this is a HUGE limitation in FortiOS. Thank you!
3 REPLIES 3
Not applicable

BTW, I also need to configure " Server 1" as the target for " PPTP Pass-Through" . I skimmed the " FortiGate_PPTP_VPN_User_Guide" , which again seems to assume that every service is running on a different box, with a 1:1 correspondence between public and private IP addresses. What am I missing?
rwpatterson
Valued Contributor III

Have you checked off the port forwarding option in the VIP mapping? This will permit you to map one port to one server from a single public address.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Thanks, that was it. This is my first real router and the number of options are a bit overwhelming at times.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors