Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Antti
New Contributor

Port forwarding from IP-range to single IP

Hi,

 

I'm quite new to the world of FortiGate.

 

I need to forward traffic from IP-range to specific ports of certain device.

(Everything from IP 123.123.123.XXX --> 192.192.192.123 TCP 111, 222 and UDP 111, 222)

 

What is the best way to do this? At the first glance with the VIPs I would be have to make four digit number of rules.

The firewall in use is FortiGate 60E

 

-Antti

 

 

13 REPLIES 13
anasalomari
New Contributor

Hello,

 

You need to create 2 VIP objects one for each port .

then create VIP group, after that add these objects to that group.

finaly, apply policy to the VIP group.

 

Anas

 

GusTech
Contributor II

You solve this with virtual IP. Yes, i would be nice to attach more ports at the same vip rule. Now you need one for each if its not in same range. But, you can group them in one vip group.

 

Fortigate <3

Fortigate <3
Antti
New Contributor

Thank you for the answers.

 

My problem here is that the incoming connection isn't an specific ip, but IP range 123.123.123.0-123.123.123.255. And all of them should point to single IP. If I set the external IP to range xxx.xxx.xxx.0-xxx.xxx.xxx.255 the mapped IP must be .0 - .255 also. But I need it to point single IP. Is this sovled using source address filter or something similar?

anasalomari

hello,

 

you can note add multi-ports to one VIP.

 

Anas

 

GusTech

anasalomari@hotmail.com wrote:

hello,

 

you can note add multi-ports to one VIP.

 

Anas

 

You can only add singel port or range, not many singel individual ports.

 

Fortigate <3

Fortigate <3
Antti

The main problem I'm having is that the incoming IP can be anything between xxx.xxx.xxx.0 - xxx.xxx.xxx.255.

In VIP settings, when the external ip is between .0 - .255 the mapped ip is also the same range. But in this case it should be single mapped ip.

 

Is this done using Source Address Filter? Or how i forward the traffic from .0 - .255 to single IP?

GusTech
Contributor II

Please explain some more, do i understand your last post correct if this is the case:

 

You have a /24 subnet in external/WAN, and you want to NAT all the /24 addresses to on singel ip in the same subnet?

Fortigate <3

Fortigate <3
Antti
New Contributor

Yes,

 

Information is coming from /24 subnet and we need to receive the information in an specific machine.

I'd know how to conf the VIP if the case was f.ex. from 123.123.123.321 ----> 192.192.192.291. But it is 123.123.123.0/24 -----> 192.192.192.291.

GusTech
Contributor II

Ok, setup:

External IP address/Range 0.0.0.0 - 0.0.0.0

Mapped IP Address/Range machine - machine

 

Create a policy from WAN to your machine interface that control access to ports 

Fortigate <3

Fortigate <3
Labels
Top Kudoed Authors