Skip to main content
smartgate
Visitor III
January 31, 2024
Question

SNAT for two ISP routes on Fortigate

  • January 31, 2024
  • 2 replies
  • 1174 views

스크린샷 2024-01-31 112659.png

hello
We are trying to obtain two ISP lines by adding a new ISP line to the existing single ISP line configuration.
I don't know yet whether these two will be configured as active-active or active-standby.
SNAT is required for both lines, and in the case of Active-Active, two IP pools will be applied to the policy to enable sequential NAT processing.
However, when operating as active-standby, I do not know how to switch the SNAT IP in the firewall when switching lines.
If you have experience or know anything about this situation, please help.

 

2 replies

AEK
SuperUser
SuperUser
January 31, 2024
AEK
hbac
Staff
Staff
January 31, 2024

Hi @smartgate,

 

FortiGate will SNAT the traffic to ISP1 or ISP2 IP address based on outgoing interface. You don't have to switch the SNAT IP in the firewall when switching lines. The FortiGate will do it for you.

 

If you are using SDWAN, please make sure to configure performance SLA to update the static route in case the ISP is down.

 

If you are not using SDWAN, you can configure link-monitor to update the static route. 

 

Regards, 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!