Skip to main content
ispcolohost
New Member
April 1, 2021
Question

1:1 static NAT that only affects traffic from one interface?

  • April 1, 2021
  • 6 replies
  • 7733 views

When adding a Virtual IP mapping, i.e. 1:1 NAT, the Fortigate has an Interface box, which you'd think would actually perform some role, such as isolating the NAT to the interface in question.  In reality, adding a Virtual IP seems to affect traffic to the IP in question across all interfaces, regardless of the interface setting.

 

We have a situation where traffic traversing a Fortigate through a large number of interfaces should flow exactly as the rules allow, and no virtual IP's are involved.  The same Fortigate has dial-up ipsec VPN users, and for them specifically, we need them to have traffic intended for a public-facing IP get remapped to a private IP out a different interface, because DNS points everything to the public IP.  I added a Virtual IP with the mapping in question of public to private, and set the interface to be the VPN interface, but that immediately broke all other traffic traversing the firewall to the public IP because it began trying to rewrite everything.

 

Is there a workaround for this?  and what's the point of the Virtual IP rule interface box since it seems to cause the same problem whether set to an interface or set to Any?

    6 replies

    lobstercreed
    New Member
    April 1, 2021

    There isn't much function to the interface box in the GUI.  I would say it serves roughly the same purpose as the same box for a regular firewall address definition.  The address/VIP doesn't appear as an option unless you select that interface, so it could be helpful in avoiding mistakes/reducing clutter in the GUI.

     

    Having said that, what you want I think does exist (I've never used it) in the CLI but it is called srcintf-filter:

    https://docs.fortinet.com/document/fortigate/6.4.5/cli-reference/293620/config-firewall-vip  Let me know if that works.  I've never needed it, but I could see it being useful for me in a couple scenarios down the road.

    ispcolohost
    New Member
    April 1, 2021

    Thanks for the tip.  I just tried; it didn't work, still broke all traffic through the Fortigate when in place.

    ispcolohost
    New Member
    April 1, 2021

    I'm going to see if the DNS translation stuff works interface-specific or breaks everything too :)

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!