Skip to main content
dtap
New Member
January 14, 2019
Question

Fortigate in Azure triple-NAT

  • January 14, 2019
  • 1 reply
  • 2946 views

I just setup a Fortigate NGFW in a VM in Azure, but I realized I would be adding 2 additional layers of NAT in front of my load-balaced web servers. Meaning, now (ELP=External Load Balancer;PIP=Public IP; ILB=Internal Load Balancer): ELB PIP --->(NAT)---> VM internal IP with firewall: Firewall PIP --->(NAT)---FW internal IP--->(NAT)---ILB--->(NAT)---VM internal IP

I don't think triple NAT can be considered an optimal setup. Am I just doing this wrong?

 

    1 reply

    emnoc
    New Member
    January 14, 2019

    It's not ideal but something it's the law of the jungle and you have no other options. Ideally you want  NAT simplified but even in AWS with EIP, you have the same issues sometimes.

     

    It make gathering logging and details about session flow harder to track also.

     

     

    ken

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!