Question
Outbound static NAT
Hi all We are currently migrating from another firewall product to Fortigate (including a FortiManager). What I' m trying to achieve is the same NAT topology as before. Let' s assume the external IP of the firewall is x.y.z.100. I) Internal Server 10.1.2.10 should have IP number x.y.z.101 on the outside. II) Internal Server 10.1.2.11 should have IP number x.y.z.102 on the outside. III) Internal Server 10.1.2.11 should have IP number x.y.z.103 on the outside. IV) All other clients should have IP number x.y.z.104 on the outside (not the firewall' s IP address). For IV I assume it would be sufficient to create a dynamic IP Pool with only one address in it on the FortiGate and enable " NAT" and " Dynamic IP Pool" in FortiManager for the rules concerned. - Is this correct like this? - Also, would it be possible to set up several many-to-one NAT pools for different client IP ranges, so that different internal client groups always get mapped to the same NAT address? For the internal servers I' m a bit at a loss. I' ve tried with " virtual IP" settings but these seem to only work on connections inbound from the external interface. How can I get that to work from both sides, so that when one of the internal servers opens a connection to the Internet it get' s natted to it' s personal external IP address (Static NAT in " checkpoint lingo" )? Thanks a lot Lukas