Gateway mode deployment Example 3: FortiMail unit in DMZ
FortiMail™ Secure Messaging Platform Version 4.0 Patch 1 Install Guide
Revision 2 115
http://docs.fortinet.com/ • Feedback
To add a wan1 virtual IP for the FortiMail unit
1 Go to Firewall > Virtual IP > Virtual IP.
2 Select Create New.
3 Complete the following:
4 Select OK.
To add a wan1 virtual IP for the protected email server
1 Go to Firewall > Virtual IP > Virtual IP.
2 Select Create New.
3 Complete the following:
4 Select OK.
To add a internal virtual IP for the FortiMail unit
1 Go to Firewall > Virtual IP > Virtual IP.
2 Select Create New.
3 Complete the following:
Note: To add virtual IPs, the FortiGate unit must be operating in NAT mode. For more
information, see the FortiGate Administration Guide.
Name Enter a name to identify the virtual IP entry, such as
FortiMail_VIP_wan1.
External Interface Select wan1.
Type Select Static NAT.
External IP
Address/Range
Enter 10.10.10.1.
Mapped IP
Address/Range
Enter 192.168.1.5.
Name Enter a name to identify the virtual IP entry, such as
protected_email_server_VIP_wan1.
External Interface Select wan1.
Type Select Static NAT.
External IP
Address/Range
Enter 10.10.10.1.
Mapped IP
Address/Range
Enter 172.16.1.10.
Name Enter a name to identify the virtual IP entry, such as
FortiMail_VIP_internal.
External Interface Select internal.
Type Select Static NAT.
External IP
Address/Range
Enter 172.16.1.2.
Mapped IP
Address/Range
Enter 192.168.1.5.