create_port_forward
Create a port forward (VIP) to redirect external traffic to an internal IP and port, and attach it to an existing policy to avoid policy limits.
Instructions
Create a port forward (VIP): traffic arriving on extintf at extip:extport goes to mappedip:mappedport. A VIP only passes traffic once a policy from extintf uses it as a destination. With attach_to_policy, the VIP is added to that existing policy's destinations instead of needing a new policy (the evaluation license allows only 3). FortiOS does not allow VIPs and ordinary addresses in the same policy's destinations, so the target must already use only VIPs, or pass replace_destinations=true to turn it into a VIP-only policy (its old destinations stop being reachable through it). In that policy, services match the mapped (internal) port.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | VIP name, e.g. VIP-TRAEFIK-HTTPS | |
| vdom | No | VDOM (default: FORTIGATE_VDOM, usually root) | |
| extip | No | External IP (default 0.0.0.0 = the extintf's own address) | |
| extra | No | Extra FortiOS attributes merged into the request body as-is (hyphenated keys) | |
| comment | No | Comment | |
| extintf | Yes | Interface the traffic arrives on, e.g. port1 | |
| extport | Yes | External port or range, e.g. 8443 | |
| mappedip | Yes | Internal IP or range a-b, e.g. 192.168.150.10 or 192.168.150.10-192.168.150.12 | |
| protocol | No | tcp (default), udp or sctp | |
| mappedport | No | Internal port or range (default: same as extport) | |
| attach_to_policy | No | Add this VIP to an existing policy's destinations (recommended) | |
| replace_destinations | No | With attach_to_policy: replace the policy's ordinary-address destinations with this VIP |