Skip to main content
Unai_SecFnet
New Member
February 21, 2022
Question

Central SNAT controlled with destination port

  • February 21, 2022
  • 5 replies
  • 2587 views

HI!

 

Does anybody know if exist the possibility of configuring and controlling central SNAT using the destination port? I mean, could you make the firewall SNAT HTTPS traffic and not SSH traffic, for example?

 

I think that it is not possible, in the version I am using, 6.0.13, but I would like to check if it is as I expect.

 

Thanks for support!

5 replies

Debbie_FTNT
Staff & Editor
Staff & Editor
February 22, 2022

Hey Unai,

as far as I can tell, SNAT can only be set according to source port and IP protocol (TCP/UDP/ICMP/etc), but not destination port or service, even in newer versions.

The only way I have been able to find is with different policies with different NAT settings (no central NAT)

-> policy 1 applies to HTTPS, NATs to pool1

-> policy2 applies to SSH, NATs to pool2

Unai_SecFnet
New Member
February 23, 2022

Hey debbie,

 

It is as I thought, it is a big problem not to control the SNAT using the service or destination port.

 

 

 

Debbie_FTNT
Staff & Editor
Staff & Editor
February 24, 2022

Hey Unai,

I'm sorry I didn't have better news for you. You can reach out to your local Sales representative for a feature request, to have the option of destination port/services added to central SNAT.

heljag
Staff
Staff
September 25, 2025

This is an old topic that has remained unanswered, but this is possible since 7.2.8 and 7.4.x.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-the-destination-port-for-the-Central/ta-p/256507

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!