Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Unai_SecFnet
New Contributor II

Central SNAT controlled with destination port

HI!

 

Does anybody know if exist the possibility of configuring and controlling central SNAT using the destination port? I mean, could you make the firewall SNAT HTTPS traffic and not SSH traffic, for example?

 

I think that it is not possible, in the version I am using, 6.0.13, but I would like to check if it is as I expect.

 

Thanks for support!

4 REPLIES 4
Debbie_FTNT
Staff
Staff

Hey Unai,

as far as I can tell, SNAT can only be set according to source port and IP protocol (TCP/UDP/ICMP/etc), but not destination port or service, even in newer versions.

The only way I have been able to find is with different policies with different NAT settings (no central NAT)

-> policy 1 applies to HTTPS, NATs to pool1

-> policy2 applies to SSH, NATs to pool2

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Unai_SecFnet

Hey debbie,

 

It is as I thought, it is a big problem not to control the SNAT using the service or destination port.

 

 

 

Debbie_FTNT

Hey Unai,

I'm sorry I didn't have better news for you. You can reach out to your local Sales representative for a feature request, to have the option of destination port/services added to central SNAT.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Unai_SecFnet

I checked that this is possible in the 7.0.x version, but upgrading to that version is not a option for us

Labels
Top Kudoed Authors