Skip to main content
smilings
Explorer
November 6, 2025
Solved

Creating a NAT in Fortigate 120G

  • November 6, 2025
  • 1 reply
  • 476 views

Currently we have a Cisco Firewall that has multiple NAT rules for Citrix applications. Now we are adding a Fortigate FW in front of the Cisco Firewall and it blocks Citrix applications. Do I need to create the same NAT rules on the Fortigate FW or could I create a range to allow all the NAT rules through the Fortigate. What would you suggest?

 

NAT Rules Fortinet.png

Best answer by ede_pfau

Hello,

and welcome to the forums.

Depends on the NAT rules. I assume they translate the WAN IP to some internal address, and if you put a FGT in front, the WAN address remains with the FGT and all addresses behind it will be of private networks.

Works as designed.

If you absolutely do not want to rewrite your NAT rules (which would be the straightforward solution), maybe you could deploy the FGT in Transparent mode. Basically, the FGT will act like a Layer 2 device, bear no IP addresses and will not route.

I once had a situation where I had to protect a weak (competitor's) firewall quickly, and put a TP mode FGT in front. No changes to the protected network at all, high rate of blocking attacks, happy customer.

 

1 reply

ede_pfau
SuperUser
ede_pfauAnswer
SuperUser
November 6, 2025

Hello,

and welcome to the forums.

Depends on the NAT rules. I assume they translate the WAN IP to some internal address, and if you put a FGT in front, the WAN address remains with the FGT and all addresses behind it will be of private networks.

Works as designed.

If you absolutely do not want to rewrite your NAT rules (which would be the straightforward solution), maybe you could deploy the FGT in Transparent mode. Basically, the FGT will act like a Layer 2 device, bear no IP addresses and will not route.

I once had a situation where I had to protect a weak (competitor's) firewall quickly, and put a TP mode FGT in front. No changes to the protected network at all, high rate of blocking attacks, happy customer.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!