Skip to main content
Best answer by sw2090

there is also a known bug with vip nt beeing displayedin policy manager when the ipv6 settings are incorrect. FGT and FMG do accept these settings (and do not accept the default Fortinet puts in there when you create a VIP) but the VIP is not displayed  in policy manager afterwards.

This can  be resolved by clearing out the ip v6 addresses in the vip and save it.

Unfortunately there is no switch to completely disable v6 in a vip :(

11 replies

Christian_89
Contributor III
February 9, 2023

Is the interface in the policy correct?
First select the interface from where you come and then the interface where you want to go.
Then the target system should be selectable.

tanaki
tanakiAuthor
New Member
February 9, 2023

Only limited list of addresses appear in Destination,   there is no  single member of VIP.

Incoming and outgoing interfaces are OK.

Staff
February 9, 2023

Hello Tanaki, 

Since you are using FGT in policy mode I suppose you already have central NAT enabled, right? 

When Central NAT is enabled, it is not necessary to add the VIP object into the firewall policy as the destination address. This is normal behaviour due to the fact that, in a Central NAT status, the DNAT is injected into the kernel since the object is created into the Policy & Objects -> DNAT & Virtual IPs.

Create the firewall policy and in the destination field, select the local IP configured into the VIP.



You can refer to the below KB for VIP configuration: 
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-firewall-policies-for-a-VIP-when-Central/ta-p/197615

tanaki
tanakiAuthor
New Member
February 9, 2023

Thank you,

I think Central NAT is disabled, how is it possible to check its status?

Staff
February 9, 2023

Central NAT should already be enabled by default in case your device is in Policy Mode. 
Should be visible under Policy & OBjects > Central NAT in the GUI or by running the below command in the CLI:

show full system settings | grep "central-nat"

sw2090
SuperUser
sw2090Answer
SuperUser
February 10, 2023

there is also a known bug with vip nt beeing displayedin policy manager when the ipv6 settings are incorrect. FGT and FMG do accept these settings (and do not accept the default Fortinet puts in there when you create a VIP) but the VIP is not displayed  in policy manager afterwards.

This can  be resolved by clearing out the ip v6 addresses in the vip and save it.

Unfortunately there is no switch to completely disable v6 in a vip :(

tanaki
tanakiAuthor
New Member
February 10, 2023

Quite odd TBH, I am new to Fortinet,  've been  using Cisco, pFsense, Wrt  etc.  for years no such generic flaws

gfleming
Staff
Staff
February 10, 2023

Not completely related to your question but may I ask what the decision was behind using Policy-based NGFW? It's generally recommended to run FortiGate as Profile-based.

tanaki
tanakiAuthor
New Member
February 27, 2023

Because it says it's more advanced mode

AMAK
Visitor III
March 14, 2023

Any luck resolving it? I too seem to get this issue.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!