Fortigate 500D - NAT Entire Subnets
Hello,
I'm having some trouble with NAT'ing entire subnets and am looking for suggestions and/or confirmation that I am doing it correctly.
I'm trying to give each school a separate external IP address based on their subnets. I am doing the following to create the NAT rule.
1)Create Address Object for the school site's subnet
-School 1 - 10.1.0.0/16
-School 2 - 10.2.0.0/16
-School 3 - 10.3.0.0/16
2)Create IP Pool Object for each external IP address (All 3 IP addresses are part of a Single WAN interface network)
-Set "TYPE" to overload (Per Fortinet Chat Support)
3)Create IPV4 Policy
-School 1 NAT Policy:
-Incoming Interface - LAN
-Outgoing Interface - WAN
-Source: School 1 - 10.1.0.0/16
-Destination: ALL
-Schedule: Always
-Service: ALL
-Action: Accept
-Firewall/Network Options
-NAT: On
-IP Pool Configuration: Use Dynamic IP Pool
-<Overload IP POOL Object I created>
When I apply this rule I lose all access to the internet.
At one school site, it works for the wired connections, but not for the wireless connections. As soon as I toggle the rule off, internet connectivity returns for all subnets.
If I do a tracert from a machine that can no longer get out to the internet I successfully hit my Fortigate 500D and then drop all other attempts to reach the outside.
Can anyone confirm this is the correct process for what I am trying to do? Any suggestions where I should be looking to trouble shoot this?
