Skip to main content
rcpdkc
Explorer II
October 31, 2025
Solved

Fortigate Gateway NAT Problem

  • October 31, 2025
  • 8 replies
  • 966 views

I have a Fortigate firewall. The management IP block is 172.16.1.1/24.

Fortianalyzer(172.16.1.10) is in this range.. I have an SMTP server, and only the IP address 192.168.1.100 is allowed to access it. I can access the SMTP server by NAT my 172.16.1.10 server. However, I cannot access the SMTP server using the Fortigate management interface (172.16.1.1). NAT is not working.

Best answer by funkylicious

try adding this ip either as a secondary on a existing interface in root vdom or create a loopback and assign it that IP and see if that works.

8 replies

funkylicious
SuperUser
SuperUser
October 31, 2025
rcpdkc
rcpdkcAuthor
Explorer II
November 1, 2025

I entered the management interface IP address as the source IP. I also added the NAT rule, but it still isn't NAT.

funkylicious
SuperUser
SuperUser
November 1, 2025

local originating traffic from the FGT isnt subject to NAT, only for traffic passing through.

just try to enter as source the IP that is allowed on the remote SMTP, see if it works.

"jack of all trades, master of none"
ElwinBERRAR
Explorer III
November 1, 2025

The error means the IP you’re trying to use isn’t assigned to any interface in the root VDOM. You’ll need to use an IP that actually belongs to an interface in that VDOM, or create a loopback and assign it there first.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!