Skip to main content
WQTpicap
New Member
March 11, 2026
Solved

will blackhole route affect SNAT and DNAT on fortigate?

  • March 11, 2026
  • 3 replies
  • 292 views

hi, we want to add blackhole route on fortigate to save the resource. we have one public subnet for example 192.1.0.0/24.

Some IP addresses of this subnet are configured on internal servers behind the internet firewall. 

static routes are configured for this 2x IP on the firewall. 

   192.1.0.10 configured on internal server 1

   192.1.0.11 configured on internal server 2

And some IP addresses of the subnet 192.1.0.0/24 are configured on SNAT and DNAT rules. 

   192.1.0.101 is used as source NATTED IP for some internal hosts.

   192.1.0.201 is used as Destination IP on DNAT rule. 

Now we want to drop the inbound access to the rest IP addresses of the subnet 192.1.0.0/24 on firewall. We plan to add a blackhole rule on the firewall to save the resource. Will this blackhole routing rule affect SNAT and DNAT? I think it should not affect, but not very sure. 

Can anyone please help to and advise and confirm? Thanks in advance! 

 

Best answer by Toshi_Esumi

Not sure what you meant "static routes for .10 and .11 on the FGT". Do you have another router behind the FGT, which is terminating connection from the two servers? Or you meant two VIPs to map those IPs to the server's local IP?

Regardless, if the blackhole route is /24, it wouldn't affect anything configured on the FGT with an individual IP.

Toshi

3 replies

Toshi_Esumi
SuperUser
SuperUser
March 11, 2026

Not sure what you meant "static routes for .10 and .11 on the FGT". Do you have another router behind the FGT, which is terminating connection from the two servers? Or you meant two VIPs to map those IPs to the server's local IP?

Regardless, if the blackhole route is /24, it wouldn't affect anything configured on the FGT with an individual IP.

Toshi

WQTpicap
WQTpicapAuthor
New Member
March 11, 2026

Thanks @Toshi_Esumi  for your advice! we have two internal servers which the IP .10 & 11 are configured on their interfaces respectively. This 2 servers are located behind firewall and need to communicate with external without NAT. 

Toshi_Esumi
SuperUser
SuperUser
March 11, 2026

How did you do that? Unless you cut off a smaller subnet like 192.1.0.8/29 then put .9 on the FGT's interface, while those servers get .10 and .11 it wouldn't work. And if you do it like this you shouldn't need any static routes because that /29 is directly connected route and go into the routing table automatically.

Toshi

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!