Skip to main content
Silver
New Member
September 11, 2015
Question

NAT Internal Traffic

  • September 11, 2015
  • 9 replies
  • 9522 views

Dear All,

Can someone tell me why for internal traffic do we need to enable nat in the policies.

Like example;

I have the following network 192.168.1.0/24 on vlan x and network 10.64.28.0/24 on vlan y. Both vlan's are using firewall as gateway and a sub interface configured with trunk to allow both vlan's. The problem if i do not enable nat on the policies both subnet cannot communicate. 

 

Thanks

    9 replies

    gschmitt
    New Member
    September 11, 2015

    Is the FortiGate the default gateway for both VLANs? You said "firewall" but do you mean the FortiGate?

    Silver
    SilverAuthor
    New Member
    September 11, 2015

    Hi,

    Thank you for your reply. Yes Fortinet is using as gateway for both vlan's

     

     

    Silver
    SilverAuthor
    New Member
    September 18, 2015

    Hi All,

    Anyone can suggest what could be the problem.

     

    Thanks 

    Allwyn_Mascarenhas
    New Member
    September 29, 2015

    Silver wrote:

    Dear All,

    Can someone tell me why for internal traffic do we need to enable nat in the policies.

    Like example;

    I have the following network 192.168.1.0/24 on vlan x and network 10.64.28.0/24 on vlan y. Both vlan's are using firewall as gateway and a sub interface configured with trunk to allow both vlan's. The problem if i do not enable nat on the policies both subnet cannot communicate. 

     

    Thanks

    i do not get this part:

    sub interface configured with trunk to allow both vlan's.

     

    There should 2 vlan subinterfaces acting as gw for both the vlans and those 2 should behave like normal interfaces. Where does the trunk come in?

     

     

    vjoshi_FTNT
    Staff
    Staff
    September 29, 2015

    Hello,

     

    Does it happen with complete subnet or only specific hosts are tested?

    - This looks to be more of a AV/Firewall on the end user or can be another L3 device which allows traffic only from the subnet it is connected to

     

    Worth checking that part

     

     

     

     

    Silver wrote:

    Dear All,

    Can someone tell me why for internal traffic do we need to enable nat in the policies.

    Like example;

    I have the following network 192.168.1.0/24 on vlan x and network 10.64.28.0/24 on vlan y. Both vlan's are using firewall as gateway and a sub interface configured with trunk to allow both vlan's. The problem if i do not enable nat on the policies both subnet cannot communicate. 

     

    Thanks

    vjoshi_FTNT
    Staff
    Staff
    September 29, 2015

    Also, run debug flow or a simple sniffer command to see if the traffic exits the Fortigate on the egress VLAN or not.

     

     

    Silver
    SilverAuthor
    New Member
    October 2, 2015

    Hi Vjoshi,

    Thank you for your reply. This happen only with specific host but not the whole subnet. but the client did not enable the firewall or av

     

    Thanks

    Silver
    SilverAuthor
    New Member
    January 4, 2016

    i see only arp request when i did an sniffer packet

    JoRC
    Visitor III
    December 28, 2024

    Did someone find how what was the problem.
    I'm having the same problem.
    New setup with 3 interface only. WAN, Users, SRV.
    Users are not able to get DNS query from the SRV subnet/interface without Nating enable.  

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.