1:1 static NAT that only affects traffic from one interface?
When adding a Virtual IP mapping, i.e. 1:1 NAT, the Fortigate has an Interface box, which you'd think would actually perform some role, such as isolating the NAT to the interface in question. In reality, adding a Virtual IP seems to affect traffic to the IP in question across all interfaces, regardless of the interface setting.
We have a situation where traffic traversing a Fortigate through a large number of interfaces should flow exactly as the rules allow, and no virtual IP's are involved. The same Fortigate has dial-up ipsec VPN users, and for them specifically, we need them to have traffic intended for a public-facing IP get remapped to a private IP out a different interface, because DNS points everything to the public IP. I added a Virtual IP with the mapping in question of public to private, and set the interface to be the VPN interface, but that immediately broke all other traffic traversing the firewall to the public IP because it began trying to rewrite everything.
Is there a workaround for this? and what's the point of the Virtual IP rule interface box since it seems to cause the same problem whether set to an interface or set to Any?
