Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Georges_Orwell
New Contributor

What is Virtuel IP ?

Hello all, I' m sorry if my question is stupid but i' m beeginer in Firewall systems i dont anderstand the functioning and goal of Virtual IP. In our firewall Fortigate 200D there is Virtual IP item in Policy and Objects > Objects. Can you explain me simply with an exemple? Thanks you for your help Georges
3 REPLIES 3
emnoc
Esteemed Contributor III

VIP are a address that' s mapped to another ip_address or group of ip_address. This is required when your hiding server(s) behind another address and need destination NAT Most items ( host services ) in the internet are probably behind a VIP or SLB-VIP to some degree. So take a traditional VIP mypublic host 1.1.1.1. --------> 192.168.10.1. ( services http/https ) or a SLB-VIP ( server load balance with 2 servers) mypublic host 1.1.1.1 |---------> 192.168.10.1 ( services http/https ) |---------> 192.168.10.2 ( services http/https ) A traditional VIP also has a port-forrwarder function which is great when you need to map one port to another or stack multiple devices behind one address and yet require numerous services mypublic host 1.1.1.1 ( 443/25/110 ) |----443--> 192.168.10.1 ( services https ) |--- 25---> 192.168.10.2 ( services mail ) !---110---> 192.168.10.2 ( services POP ) or mypublic host 1.1.1.1 ( 443/25/110 ) |----4432--> 192.168.10.1 ( services https ) |--- 25---> 192.168.10.2 ( services mail ) !---230---> 192.168.10.2 ( services POP ) I hope that clarifies some of the VIP concepts. You can wiki VIP also if you need more information.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Christopher_McMullan

Neither to add, nor to take away from what emnoc has said: Very simply, SNAT is done through the firewall policy itself; VIPs handle DNAT. Port forwarding and virtual server load balancing branch off from the main function.

Regards, Chris McMullan Fortinet Ottawa

Georges_Orwell
New Contributor

Thank you for your responses. It' s very informative for me I understand better now Thank you to both of you
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors