Description
This article describes that with central NAT, one can not assign a Virtual Server to a policy.
It is not required to reference the virtual server configured anywhere when central NAT is enabled.
Solution
When central NAT is enabled, it is not possible to add the VIP to the firewall policies.
The same also goes for Virtual Servers that are configured with multiple real servers.
If central NAT is enabled, it will not be possible to use the virtual server in firewall policies.
Virtual server.


Related articles:
Technical Note: Configuration changes regarding Central NAT and Virtual IPs in FortiOS 5.4
Technical-Tip-Configure-a-virtual-server
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.