Skip to main content
HS08
Visitor III
August 27, 2025
Question

SDWAN with NAT

  • August 27, 2025
  • 2 replies
  • 589 views

FGT-A have 2 different link to FGT-B, 1st link must enable the NAT and the 2nd link not use NAT.

How we can create policy to enable NAT only for 1st link, since in the firewall policy we use sdwan interface for the destination?

2 replies

johnathan
Staff
Staff
August 27, 2025
Never trust a computer you can't throw out a window.
HS08
HS08Author
Visitor III
August 27, 2025

But the link should be natted and use ip from the provider. 

With this condition what should i put in start and end ip addr?

sulanmu7
New Member
August 27, 2025

Your DNATs (VIPs) must be assigned to a specific interface. You can't select an SD-WAN zone, but you can specify "any" as the source interface, then this VIP won't be associated only with a specific wan interface.