Created on
04-29-2024
10:26 PM
Edited on
06-03-2025
12:37 AM
By
Jean-Philippe_P
Description | This article describes the behavior of SNAT when VIP is configured (no port forwarding). |
Scope | FortiGate. |
Solution |
FortiGate has two options to perform SNAT, configurable in the firewall policy.
When VIP is configured as one-to-one mapping (no port-forwarding) with 'any' external interface, FortiGate will use this VIP IP address as its SNAT IP address.
Below is a firewall policy configuration example with 'Use Outgoing Interface Address' as its SNAT IP:
Below is the SNAT IP used for outbound traffic from 10.201.1.181:
Below is the Virtual IP configuration:
When the above VIP is used or referenced in a firewall policy, outbound traffic from host 10.201.1.181 will use 10.47.17.177 (VIP IP) as its SNAT IP:
Note:
Though the outgoing interface IP is 10.47.17.176, it still requires a dynamic ippool and is selected in the outbound firewall policy.
config firewall ippool
config firewall policy
Note: This scenario is valid when Central NAT is disabled on the FortiGate. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.