Skip to main content
BockChrDiakonissen
New Member
June 26, 2025
Question

Redirect all internal traffic to services (like NTP, DNS,...) at any IP to specific internal IP

  • June 26, 2025
  • 4 replies
  • 1134 views

We have switched from Sophos UTM to Fortigate and we used to have DNAT rules to redirect all internal traffic to any destination with specific service to secific internal IP. 

 

scr.ip ANY > dst.ip ANY > dst.port tcp-udp/123 > dst.ip 10.20.30.40 > dst.port tcp-udp/123
src.ip ANY > dst.ip ANY > dst.port udp/53 > dst.ip 10.20.30.50 > dst.port tcp-udp/123

I only can find DNAT via Virtual IP - but there is no option to create rules like above.

Can anyone help me out or open my eyes to find the way to go.

 

Thx and greetings
Christian 

4 replies

AEK
SuperUser
SuperUser
June 26, 2025

Try add VIP as follows:

  • Interface: internal
  • External IP: 0.0.0.0
  • Mapped IP: 10.20.30.40
  • Port forwarding: 53 mapped to 53

And add firewall rule as follows:

  • Src intf: internal
  • Dst intf: WAN (or any)
  • Src: all
  • Dst: all
  • Svc: DNS

Hope it helps.

AEK
BockChrDiakonissen
New Member
June 27, 2025

This was my first attempt. But Forti will not allow this for Ext Int.

 

0.0.0.0 --> error: IP must not be zero

0.0.0.0/0 --> error: Invalid IP Range

0.0.0.0-255.255.255.255 --> error: IP must not be zero & IP range too large for mapped IPs

AEK
SuperUser
SuperUser
June 28, 2025

Which FortiOS are you using?

On my 7.0.17 I can specify 0.0.0.0 as external IP.

vip1.png

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!