| Description | This article describes how to configure an FQDN firewall VIP to perform destination NAT. |
| Scope | Any supported version of FortiGate. |
| Solution |
Scenario 1: Redirect traffic to a FQDN address to a different FQDN address. This scenario can for example be used in case a legacy service using a FQDN address was migrated to a new FQDN address but the legacy FQDN is still in use. The goal is to forward traffic from FQDN legacy.service.com to FQDN new.service.com.
config firewall address edit "new"
Scenario 2: Perform port translation for a specific FQDN. This scenario can for example be used in case a client initiates a connection using a different port than the one the server listens on. Example: a user initiates SSH connection to new.service.com:22 but the server only accepts SSH connections on port 8022.
config firewall address end
config firewall policy |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.