Created on
07-22-2025
06:15 AM
Edited on
07-23-2025
06:38 AM
By
Jean-Philippe_P
Description | This article describes the ability to use SD-WAN zones as interface entries within Central SNAT configuration. The feature is available starting from FortiOS version 7.6.1, and has also been backported to FortiOS versions 7.4.8 and 7.2.11 (CLI only). This enhancement improves policy flexibility and routing consistency in SD-WAN-enabled environments. |
Scope | FortiGate devices running FortiOS v7.6.1 and later, as well as FortiOS versions 7.4.8 and 7.2.11 (CLI-based support). Applies to Central SNAT, Local-In, DoS, TTL, and multicast policies referencing SD-WAN zones. |
Solution |
Use Case. Previously, Central SNAT policies only supported specifying physical interfaces. Beginning with FortiOS v7.6.1, and backported to versions 7.4.8 and 7.2.11 (CLI only), SD-WAN zones can be used as destination interfaces in Central SNAT policies. This simplifies NAT rule configuration in SD-WAN deployments.
Example Configuration (Central SNAT Using SD-WAN Zone).
In this example:
Feature Availability.
Additional Policy Types Supporting SD-WAN Zones.
Operational Considerations.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.