Skip to main content
calink
Staff
Staff
July 16, 2025

Technical Tip: Policy with NAT enabled does not keep NAT setting after policy is set to DENY temporarily

  • July 16, 2025
  • 0 replies
  • 849 views
Description This article explains why a policy with NAT enabled does not keep NAT setting after policy is set to DENY temporarily.
Scope FortiGate.
Solution

Here is a normal policy with NAT enabled.

 

with NAT enabled.png

 

The same policy is now set to DENY:

 

set to Deny.png

 

The same policy set back to ACCEPT:

 

With NAT disabled.png

 

NAT is disabled by default after setting the policy back to ACCEPT. After setting the policy back to ACCEPT, re-enable NAT to ensure the same functionality as before. Antivirus, web filtering, and certificate inspection also may need to be enabled and logging may need to be turned on.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!