FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jiahoong112
Staff
Staff
Article Id 226673
Description This article describes how to set up a Single NAT VIP on the Inter-VDOM link. This is for cases where 1 VDOM has Internet access and the other VDOM does not have Internet access.
Scope FortiGate 6.0.x, 6.2.x, 6.4.x, 7.0.x 7.2.x  - Single NAT.
Solution

Topology:

 

INET_VDOM -> Internet facing VDOM

LAN_VDOM -> VDOM with no Internet; LAN VDOM. 

 

jiahoong112_1-1665989093229.png

 

Goal:

 

The result wanted is to reach the internal-LAN IP (10.177.3.1) from the External IP (10.47.19.1).

 

Create a VIP object on the Internet-facing VDOM, vipA: 10.47.19.1 -> 10.177.3.1. This VIP directly maps the external IP to the internal-LAN IP.

 

INET_VDOM (Internet facing vdom) configuration:

 

Interface:

 

jiahoong112_1-1665728847550.png

 

VIP Object:

 

jiahoong112_2-1665989252752.png

 

Firewall Policy:

 

jiahoong112_3-1665989354063.png

 

Static Route:

 

jiahoong112_4-1665989401705.png

 

LAN_VDOM (Non-Internet facing vdom) configuration:

 

Interface:

 

jiahoong112_5-1665989635392.png

 

Firewall Policy:

 

jiahoong112_6-1665989688592.png

 

Static Route:

 

jiahoong112_7-1665989731304.png

 

Result:

 

This is how the Session Table should look like.

 

Session Table Filters used:

 

# diag sys session filter ext-dst 10.47.19.1    -> (wan ip)
# diag sys session filter ext-dst 10.177.3.1    -> (internal ip)

# diag sys session list

 

jiahoong112_9-1665990326445.png

 

In this screenshot, 10.111.36.200 is the IP pinging the WAN IP of INET_VDOM.