FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
edomi
Staff
Staff
Article Id 344730
Description This article describes how VIP/DNAT lookup is done in FortiOS and how this may affect communication.
Scope All FortiOS versions.
Solution

FortiOS by design will do VIP lookup before policy lookup. If in case multiple VIPs are using the same external IP and port, matching incoming traffic used in different policies, if the VIP used in the policy allowing traffic is not the one selected by FortiOS in VIP lookup, traffic will be dropped.

 

If having multiple VIPs mapping to the same external IP:

Without port-forwarding, only the first VIP will be matched, for any traffic destined to the external IP. This will cause traffic for policies with the other VIPs applied not to be matched.

 

With one or more VIPs with port-forwarding, make sure to place those above VIPs without port-forwarding enabled, otherwise, traffic will match the first VIP therefore the policies with the other VIPs will not be matched.

 

packet life.png

 

Related Documentations:

Destination NAT

Configuring VIPs