Skip to main content
johnlloyd_13
Explorer III
November 11, 2024
Solved

Configuring FW Policy with NAT in an internet VDOM setup

  • November 11, 2024
  • 8 replies
  • 2333 views

hi,

i plan to configure SNAT in a FG with multiple VDOMs.

i currently have the "internet VDOM" topology wherein "internet" VDOM act as our internet edge device and all downstream VDOMs will connect/flow through it to go to the public internet.

my question, if i create a FW policy WITH SNAT in "VDOM-1", do i also create FW policy WITHOUT NAT in "internet VDOM" for traffic flow continuity?

 

image.png

 

 

Best answer by Toshi_Esumi

Yes. If that VDOM customer/users need to use just one NAT outside/public IP, that's all you need. However, you have to assign at least /31 public subnet to the npu-vlink interface and each side (root and customer vdom side) takes one IP out of the /31.

Toshi

8 replies

funkylicious
SuperUser
SuperUser
November 11, 2024

Hi,

Usually, in VDOM1/2 where the internet links are not directly connected, you would not need to activate NAT.

Assuming you have the correct routes back to VDOM1/2 in the Internet VDOM to the networks, you would only need to activate NAT in that VDOM where the traffic exists to reach the internet, Internet VDOM.

"jack of all trades, master of none"
johnlloyd_13
Explorer III
November 11, 2024

hi,

so i just need to provision FW policy with NAT in the "internet" VDOM only?

then just routing and FW policy in "VDOM-1"?
would i need 2 FW policy, i.e. first FW policy is the vlink (to internet VDOM) to "inside" interface of VDOM-1, second FW policy is the reverse, i.e. "inside" interface of VDOM-1 to vlink?

funkylicious
SuperUser
SuperUser
November 11, 2024

You would need a firewall policy in VDOM1, from LAN to vdom-link, allowing the traffic, no NAT.

In INT ( Internet ) VDOM, a firewall policy from vdom-link towards the WAN interface with NAT active.

Since FortiGate it's a stateful firewall, you would not need firewall rules in reverse created.


TLDR;

VDOM1: LAN > vdom-link ( accept, no NAT )

INTERNET: vdom-link > WAN ( accept , NAT )

"jack of all trades, master of none"
johnlloyd_13
Explorer III
November 11, 2024

hi,

thanks for your answers! appreciate them.

another question, can i do NAT in "VDOM-1" since it has a private (inside) interface/IP and public (outside) vlink interface/IP?

the "internet" VDOM has vlinks (using public IP) in downstream VDOMs (i.e. VDOM-1, VDOM-2, etc), outside interface using public IP and configured with iBGP with our internet edge router?

what will be the FW policy and NAT would look like in this scenario?

joninte2
New Member
November 11, 2024

Separating interfaces into vdoms just to keep them separate is not necessary. A firewall will not allow traffic from one interface to another unless there is a policy or unless they are in a zone or switch together (and even then this isn’t necessarily default behaviour). FortiGates need rules and routes https://tutuapp.uno/ .

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.