| Description | This article describes the steps to change the Firewall Source-NAT policy rule order via CLI commands. |
| Scope | FortiADC. |
| Solution |
FortiADC Firewall Policy or NAT-SNAT Policy rules can be a long list of policy rules. The order sequence of the Firewall Policy and NAT-SNAT can matter as the rules are executed from top to bottom of the list. Unlike FortiGate, FortiADC does not support dragging the policy rules to change the order sequence; the 'Move Up' or 'Move Down' buttons are the only options in FortiADC management GUI to change the policy rules order sequence.
To quickly change the sequence order of FortiADC Firewall Policy or NAT-SNAT Policy rules, CLI commands can be used to achieve that.
Change FortiADC NAT-SNAT Policy sequence order using CLI commands:
config firewall nat-snat move SNAT01 before SNAT02 end
config firewall nat-snat move SNAT01 after SNAT100 end
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.