Skip to main content
msoliman07-atos
New Member
July 5, 2024
Solved

NAT (IP Pools) and Zone

  • July 5, 2024
  • 2 replies
  • 2318 views

Hi everyone,

I have the topology below, WAN-1 & WAN-2 are in the same Zone (Internet) with a fail-over scenario between WAN-1 (Primary) and WAN-2 (Backup), what I want to achieve is to create 2 IP Pools as follows to use as a NAT in the outbound policy:
1. IP Pool For WAN1: Mail-Server-WAN1: 195.1.1.10 --> 192.168.100.100
2. IP Pool For WAN2: Mail-Server-WAN1: 88.31.25.10 --> 192.168.100.100

If I create an IPv4 Policy, Source: the mail server 192.168.100.100/32, Destination: 0.0.0.0/0 and put the 2 IP Pools as a Dynamic IP Pool this will work without problem in case of a fail-over will happen.
If not, what is the right approach for such a scenario?

 

2024-07-05_16-21.png

Thank you so much in advance, much appreciated.


Best answer by hbac

Hi @msoliman07-atos,

 

Your configuration is correct as per this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-associate-a-NAT-pool-IP-pool-to-a-physical/ta-p/189738

 

Regards, 

2 replies

hbac
Staff
hbacAnswer
Staff
July 5, 2024

Hi @msoliman07-atos,

 

Your configuration is correct as per this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-associate-a-NAT-pool-IP-pool-to-a-physical/ta-p/189738

 

Regards, 

msoliman07-atos
New Member
July 8, 2024

Great, Thanks

The missing configuration was to associate every IP pool with its physical interface.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!