11-13-2023 06:17 PM
Can anyone give me some insight as to how "other" public ip address can be used?
I have heard that people use 1 ip for WAN, another ip for cctv and another for mail server.
It would be better if I have a network diagram to better illustrate this.
Because I have only heard about it but not actually done it.
Solved! Go to Solution.
11-13-2023 10:54 PM
OK @Iloveyou
Replace the 2 PC with mail server and the other cctv.
The Router on the top perform NAT. /29 public bloc dedicated. Gateway stand for ISP as example.
11-13-2023
06:41 PM
- last edited on
11-15-2023
03:58 PM
by
Translator
@Iloveyou hi, you can use other IPs by creating NAT in your router or Firewall.
for Ex. check VIP option for the FortiGate firewalls. we can create VIPs to advertise other IPs towards WAN side.
Firewall-------------------------------------------------------------------WAN router
interface 1 - IP address 1.1.1.1/29
VIP address 1.1.1.2/29
VIP address 1.1.1.3/29
11-13-2023 09:54 PM
Hello!
You can use multiple IP's on the outside router/firewall by using NAT. And with nat you can use multiple IP's and "bind" them to different back end servers.
For more info about the configuration and what device you want to use it on write.
BR
11-13-2023 09:57 PM
"You can use multiple IP's on the outside router/firewall by using NAT. And with nat you can use multiple IP's and "bind" them to different back end servers. "
Yes I know this. But an actual diagram or illustration on how i configure multiple public ip on a firewall will be useful because I have not actually seen it before.
11-13-2023 10:12 PM - edited 11-13-2023 10:13 PM
Hello @Iloveyou
Using separate public IP addresses for different purposes can enhance security and optimize network services.
You might use different public IPs:
"WAN IP":
This is the primary IP address for general internet access. In a business setting, it might be used for regular web browsing, application access, etc...
-CCTV IP:
A dedicated public IP for CCTV cameras. Enhances security by isolating CCTV traffic from other internet traffic. Allows for specific firewall rules or bandwidth allocation for CCTV-related activities.
-Mail Server:
A dedicated public IP for hosting a mail server. Separates mail traffic from other internet activities. Can be beneficial for managing email-related security and performance.
Each public IP address serves a specific purpose, and this segmentation can provide benefits like
-Security isolation: Traffic for different services is kept separate, reducing the risk of vulnerabilities in one service affecting others.
-Trafic management: Dedicated IPs allow for customized traffic shaping, QoS policies, and firewall rules for each service.
-Service reliability: If one service experiences issues or comes under attack, others may remain unaffected.
11-13-2023 10:20 PM
Yes. I understand this.
But a sample network diagram and how they separate the public LAN ips will be good.
11-13-2023 10:54 PM
OK @Iloveyou
Replace the 2 PC with mail server and the other cctv.
The Router on the top perform NAT. /29 public bloc dedicated. Gateway stand for ISP as example.
11-14-2023 12:27 AM
Assume you have one public IP for internet for inside host and you have http server inside also.
Now try use acl to all any access to http and deny other and make host inside access http outside.
If you can not then using two or more public is solution.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide