{"id":305,"title":"FortiGate'de Virtual IP (VIP) ve Port Y\u00f6nlendirme (Port Forwarding) Konfig\u00fcrasyonu","content":"FortiGate g\u00fcvenlik duvarlar\u0131nda d\u0131\u015f a\u011fdan i\u00e7 a\u011fdaki sunuculara eri\u015fim sa\u011flamak i\u00e7in Virtual IP (VIP) ve port y\u00f6nlendirme i\u015flemleri kullan\u0131l\u0131r. <h2>Virtual IP (VIP) Nedir?<\/h2> FortiGate'de Virtual IP, harici IP adresini i\u00e7 a\u011fdaki bir sunucunun IP adresine e\u015flemenizi sa\u011flar. Bu sayede d\u0131\u015far\u0131dan gelen belirli ba\u011flant\u0131lar i\u00e7 a\u011fdaki sunuculara y\u00f6nlendirilebilir. <h2>Ad\u0131m Ad\u0131m Port Y\u00f6nlendirme Konfig\u00fcrasyonu<\/h2> <h3>1. Virtual IP (VIP) Olu\u015fturma<\/h3> &nbsp; 1. FortiGate y\u00f6netim paneline giri\u015f yap\u0131n 2. **Policy &amp; Objects** &gt; **Virtual IPs** men\u00fcs\u00fcne gidin 3. **Create New** butonuna t\u0131klay\u0131n 4. A\u015fa\u011f\u0131daki bilgileri doldurun: - **Name**: Kural i\u00e7in bir isim (\u00d6rn: Web_Server_Port_Forward) - **External Interface**: D\u0131\u015f ba\u011flant\u0131n\u0131n geldi\u011fi interface (genellikle wan1) - **External IP Address\/Range**: D\u0131\u015f IP adresi (genellikle \"0.0.0.0\" t\u00fcm IP'ler i\u00e7in) - **Mapped IP Address\/Range**: \u0130\u00e7 a\u011fdaki sunucunun IP adresi (\u00d6rn: 192.168.1.100) - **Port Forwarding**: Enable (Aktif) - **External Service Port**: D\u0131\u015f port (\u00d6rn: 80 veya 443) - **Map to Port**: \u0130\u00e7 port (Genellikle external port ile ayn\u0131) <h3>2. G\u00fcvenlik Politikas\u0131 (Firewall Policy) Olu\u015fturma<\/h3> &nbsp; 1. **Policy &amp; Objects** &gt; **IPv4 Policy** men\u00fcs\u00fcne gidin 2. **Create New** butonuna t\u0131klay\u0131n 3. A\u015fa\u011f\u0131daki ayarlar\u0131 yap\u0131n: - **Incoming Interface**: D\u0131\u015f interface (wan1) - **Outgoing Interface**: \u0130\u00e7 interface (i\u00e7 a\u011fa ba\u011fl\u0131 olan, \u00f6rn: internal) - **Source**: Gelen trafi\u011fin kayna\u011f\u0131 (genellikle \"all\") - **Destination**: Olu\u015fturdu\u011funuz Virtual IP (Web_Server_Port_Forward) - **Service**: HTTP, HTTPS veya \u00f6zel port numaras\u0131 - **Action**: ACCEPT - **NAT**: Aktif olmal\u0131 - **Security Profiles**: \u0130htiyaca g\u00f6re ayarlanabilir <h3>3. \u00d6rnek SSH Port Y\u00f6nlendirme (2222 \u2192 22)<\/h3> &nbsp; 1. Virtual IP olu\u015ftur: - Name: SSH_Forwarding - External Interface: wan1 - External IP: 0.0.0.0 - Mapped IP: 192.168.1.150 - Port Forwarding: Enable - External: 2222 - Map to: 22 2. Firewall Policy olu\u015ftur: - Incoming: wan1 - Outgoing: internal - Source: all - Destination: SSH_Forwarding - Service: SSH (veya TCP\/2222) - Action: ACCEPT <h2>Do\u011frulama ve Test<\/h2> &nbsp; 1. Konfig\u00fcrasyonu kaydedin 2. D\u0131\u015f a\u011fdan hedef porta ba\u011flanmay\u0131 deneyin 3. FortiGate loglar\u0131n\u0131 kontrol edin: - **Log &amp; Report** &gt; **Forward Traffic** ## \u00d6nemli G\u00fcvenlik \u00d6nlemleri 1. Sadece gerekli portlar\u0131 a\u00e7\u0131n 2. M\u00fcmk\u00fcnse source IP restriction ekleyin 3. D\u00fczenli olarak loglar\u0131 kontrol edin 4. Port y\u00f6nlendirmelerini g\u00fcncel tutun <h2>CLI ile Konfig\u00fcrasyon (Alternatif Y\u00f6ntem)<\/h2> &nbsp; SSH ile FortiGate'e ba\u011flanarak a\u015fa\u011f\u0131daki komutlarla da port y\u00f6nlendirme yapabilirsiniz: ```bash config firewall vip edit \"Web_Server_VIP\" set extintf \"wan1\" set portforward enable set extip 0.0.0.0 set mappedip \"192.168.1.100\" set extport 80 set mappedport 80 next end config firewall policy edit 0 set name \"Web_Server_Policy\" set srcintf \"wan1\" set dstintf \"internal\" set srcaddr \"all\" set dstaddr \"Web_Server_VIP\" set action accept set schedule \"always\" set service \"HTTP\" set nat enable next end ```","excerpt":"FortiGate g\u00fcvenlik duvarlar\u0131nda d\u0131\u015f a\u011fdan i\u00e7 a\u011fdaki sunuculara eri\u015fim sa\u011flamak i\u00e7in Virtual IP (VIP) ve port y\u00f6nlendirme i\u015flemleri...","created_at":"2021-07-23 20:46:48","updated_at":"2026-09-23 13:07:40","category_id":6,"view_count":499,"reading_time":3,"status":"published","editor_choice":0,"is_editor_choice":0,"published_at":"2021-07-23 20:46:48","featured_image":"resimyok.jpg","slug":"fortigate-virtula-ips-port-yonlendirme","category_name":"Sistem","category_slug":"sistem"}