Jump to:navigation, search
Wiki





























De.png
En.png
Fr.png






Configuration of port forwarding
Last adaptation to the version: 12.6.0
New:
  • Updated to Redesign of the webinterface
notempty
This article refers to a Resellerpreview

12.2 11.7

Access: UTM-IP:Port or UTM-URL:Port
Port as configured at Network / Appliance Settings / Webserver
Default-Port: 11115
i.e.: https://utm.ttt-point.de:11115
Default: https://192.168.175.1:11115
Firewall Packetfilter

Use of port forwarding

Many companies do not have a subnet with external IP addresses available. All computers are in a private network and are connected behind the IP of the router.
Port forwarding is used to forward requests on specific ports directed to the router's public IP to the internal server so that it can be reached from the Internet.

  • Network objects and services only need to be created if they do not already exist on the firewall in the form described here.
  • Objective: To make an internal server accessible from the Internet.



Configuration of the appliance

Create network object

For simple port forwarding, the server must first be created as a network object.
This must be done by clicking on → Firewall →Network objects Button Add object.


Caption Value Description Add Network Object UTMuser@firewall.name.fqdnFirewallNetwork Objects UTM v12.6 Portweiterleitung Netzwerkobjekt hinzufügen Server-en.pngCreate network object
Name: Server Assign a unique name
Type: Host Select destination NAT
Address: 203.0.113.0/---  Enter IP address of the server
Zone: internal Select "internal" as zone
Save and close Save the network object and close the dialog.


Create firewall rules

A firewall rule with destination NAT must be created so that external users can now also access the server.
This must be done by clicking Firewall Packetfilter  Button Add Rule.
The rule must then be created as follows:


General
Source: World.svg Internet Allows the Internet as the source of the data packet Add Rule UTMuser@firewall.name.fqdnFirewallPacketfilter UTM v12.6 Portweiterleitung Paketfilterregel anlegen-en.pngAdd firewall rule
Target: Host.svg Server Allows the server to be the destination of the data packet
Service: Tcp.svg https Desired service with deposited port
Action: ACCEPT Forwards the packet
NAT
Type: DESTNAT Select destination NAT
Networkobject: Interface.svg external-interface Network object that performs the translation of the IP addresses, i.e. the "nating"
Service: Tcp.svg https Uses the selected service in the local destination network
  • Then the Update rules button must be clicked. After the last setup step has been completed, port forwarding is active.