Question
NAT outgoing traffic behind 2nd IP on interface?
FortiOS 5.0.4 on a FG100D. I want to NAT traffic coming from a specific internal subnet beind the 2nd IP on a particular Internet facing interface of the FG. In the GUI, there' s two options, one I check the box for " Enable NAT" : x Use Destination Interface Address [ _ Fixed Port] _ Use Dynamic IP Pool I assume that " Use Destination Interface Address" will always use the primary IP of the destination (outgoing Internet facing) interface. Docs show that " Fixed port" relates to the source port not being changed, not to which IP is used to hide the traffic. I guess in theory I could use a Dynamic IP Pool (of the one single address, which is the 2nd IP address of the outgoing Internet facing interface), but it feels a bit off. In the CLI, I see a " set natip" option, but the docs describe that as setting up 1-to-1, and my desire here is to do typical many-to-1 NAT, just choosing a different specific 1 IP behind which to NAT all the traffic. How to? thanks! -Jay
