Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Arnold
New Contributor

forward WAN to LAN by FQND

Hi, I wnted to know those 60C with firmware 5.0 support such a feature as forward specific request to different ip' s but to the same port depending on the FQDN as in Forefront Threat Management Gateway for example if they enter adress1.company.com port forward to host 10.0.1.10:3389 and if they enter adress2.company.com port forward to host 10.0.1.11:3389

MCSE

MCSE
16 REPLIES 16
Arnold

our current situation

MCSE

MCSE
Arnold
New Contributor

and this is what we want to achieve

MCSE

MCSE
Dave_Hall
Honored Contributor

What you want is referred to is a split DNS configuration, which can be set up on 60C models and higher. See page 576 for 4.0 MR3, page 435 for 5.0 Once setup, you can create/setup DNS records for your remotes. But if your company is running a Windows Active Directory (which requires DNS be set up on it) with DHCP service running on it then the PCs in your company should already be registering themselves in AD and DNS. (The DHCP service should be registering the computer hostnames in DNS when their IP leases are renewed.)

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ScottV
New Contributor

I know exactly what you are trying to do from using a lot of ISA/TMG box' s in the past which support host header inspection where you can have multiple internal services published via one external IP and port via certificates or the like, typically though I have only used this for web services bound to certificates. I have looked into this in the past and found the FG unit cant do it as rwpatterson mentioned.
ScottV
New Contributor

Just as a side note you can use http host headers for HTTP/SSL connections under the Load Balance Virtual Server section to allow you to setup many my.server.com names and then direct them to different internal servers using the same web port via the HOST HEADER method. I thought I might be able to make it work for your scenario using TCP as the transport but it doesn' t support Host headers in that mode, which i guess makes sense as they are native to HTTP/S requests.
Dave_Hall
Honored Contributor

Scott deleted his original post regarding Load Balance Virtual Server, but he is on to something...providing all of the remotes (in the DMZ) are part of a server farm (all identical RDP servers) and it doesn' t matter which remote is used in a connect. Server Load Balancing with Port Forwarding can be set up to map an ext IP to a range (pool) of IP addresses (in the DMZ). Unfortunately (if I read the 5.0 CLI ref manual correctly) you are limited to a pool of something like 8 real servers.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ScottV

Yeah I posted thinking I had it working but it was just doing a round Robin to my RDP test box' s so I then removed the post. With the Pool setup like you say how can you distinguish which sever you want to connect to from the external source.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors