Description |
This article describes a behavior where users correctly configured Central NAT, but the preservation works intermittently. |
Scope | FortiGate with Central NAT and SD-WAN. |
Solution |
See Technical Tip: How to preserve source port when central NAT is enabled for a description on how to configure central NAT to preserve source port.
If it does not work, check the following:
config firewall central-snat-map
In this case, format the FortiGate to factory settings, and upload the firmware and the backup again.
Technical Tip: Formatting and loading FortiGate firmware image using TFTP.
get router info routing-table details x.x.x.x <----- Replace x.x.x.x with the destination IP.
Remember the evaluation order of the Packet in FortiGate is:
Packet -> Route evaluation -> FW policies -> Central Nat -> Internet.
If there are multiple ISP interfaces to get the central NAT destination, check the SD-WAN rules.
Create an SD-WAN rule or PBR using the Central NAT interface to force the traffic for the intended destination.
config router policy
di sys session filter src x.x.x.x di sys session clear di sys session list |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.