Skip to main content
Contributor III
August 30, 2008
Question

PBR-NAT or Route

  • August 30, 2008
  • 8 replies
  • 3659 views
Hi all, Does PBR do " NAT" or " Route" traffic on outgoing interface,or it looks at firewall policy for deciding which one to choose? Best, Kamyar

    8 replies

    UkWizard
    New Member
    August 30, 2008
    policy based routing has nothing to do with the firewall rules or NAT. Think of it as an override to the static route(s). used for bending traffic based on matching one of more of the following; Source IP/Subnet Dest IP/Subnet Traffic Type Service (Dest port) Really only useful for multiple wan link setups. -Nat is determined by the firewall rule the traffic hits.
    Contributor III
    September 1, 2008
    so natting or routing must be chosen per firewall policy before PBR? Regards, Kamyar
    UkWizard
    New Member
    September 1, 2008
    No, routing is the flow of packets and is based on the static and policy based routes (policy does not mean firewall policies, thats a different entity) defined on the firewall. The FIREWALL policies (I call them rules to make it easier) are the allow/deny/encrypt rules which determines which traffic is allowed to pass and whether to scan it or NAT it. With NAT, generally, the rule of thumb is, all outbound (INT -> WAN) rules have NAT enabled, everything else doesn' t (ie INT->DMZ, WAN->INT, WAN->DMZ) When a connection comes into an interface, first it is checked to see whether its allowed (via the rules), if it is, then it will them be scanned or natted as required and then routed to where it matches based on first checking the PBR, and then the static routes if no PBR exists.
    Contributor III
    September 1, 2008
    and my understanding: FG without firewall policy(rules) does not allow any traffic even though PBR is configured and running...false ot true? Regards, Kamyar
    UkWizard
    New Member
    September 1, 2008
    yes that is correct, but as i have said, firewall rules are not related to PBR as such. A PBR would only be used if allowed by a rule.
    Contributor III
    September 1, 2008
    Thank you UkWizard...i find out now what' s happening inside of FG. Best, Kamyar
    UkWizard
    New Member
    September 1, 2008
    have a read through the manuals as their are many docs which explain how it works in great depth. Including the " life of a packet" .
    Contributor III
    September 2, 2008
    I just read " Life of a Packet" yesterday, it was great...thanks again
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.