Hi!
We have multiple Public IP adresses assigned to the fortigate vm interface in azure.
We want an internal source to use a explicit public ip for outgoing and ingoing traffic.
Incoming traffic is no problem with virtual ips, but outgoing is always the public ip from the fortigate.
the tips in this documentation do not work:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Assign-multiple-public-IP-addresses-to-For...
Any ideas how to get this to work?
thanks!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Thank you for reaching out. I am not sure if I understood the problem correctly. If you are looking to make sure traffic starting from a device behind the fortigate going to the internet always get source-nat with specific ip you can in this case create an ip-pool and specify the address to specific external ip as long as you have reserved this ip for your network and recommended to be on the same subnet as the address of the outgiong interface. The following article provide details about ippool different methods including 1-to-1, pat, dynamic, itc:
https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/29961/dynamic-snat
Thank you,
saleha
Hi @kpcsi,
You can enable nat-source-vip under your VIP. Please refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-a-VIP-s-External-IP-Address-for...
Regards,
Please follow the guide here:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.