Description | This article describes that it is not possible to connect to FortiGuard Servers with source IP setting as loopback interface private IP and configure central SNAT to public IP. |
Scope | FotiGate. |
Diagram:
source IP is set as the private Ip address under the FortiGuard server configuration.
If the upstream device (let's say ISP route) has no idea how to route back to this source IP, the connection will not be successful since FortiGuard server does not have route back to it.
Central SNAT configured for the traffic between looback interface and port 10. However, the Central SNAT rule or the firewall policy with NAT enabled (when Central NAT is off) does not apply to the local-originated traffic but only the forwarding traffic. So, the traffic originated by the FortiGate will not be NATted to port 10 IP address when going out the FortiGate at port 10.
Based on this, the source IP under the FortiGuard setting needs to be the IP allowed and reachable by the upstream. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.