Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Central NAT vs Virtual IP

MR2 added a Central NAT table. Could someone explain what a a central NAT table is used for? It seems that Virtual IPs would do the same thing as a central NAT table. Or am I missing something? I have looked through all the documentation and nothing states what it is used for and only how to set one up. If someone knows how to use it and a scenario it would be used for, that would be much appreciated. Thanks, Paul
2 REPLIES 2
rocampo
New Contributor

VIPs primarily used for Destination NAT translation, while Central NAT used for Source NAT translation. If for example you have a web or mail server that needs to be seen on the internet you use VIPs. Central NAT gives flexibility on how source address ( like internal addresses) will be translated going out the internet. You for example can define several internal addresses that would be translated to a single global address.
Maik
New Contributor II

the central nat table is just another way where/how you can nat: You were used to do Source NAT with IP Pools and Destination NAT with VIP' s. the new central NAT table helps Checkpoint users to accommodate a bit faster on Fortigates :) ->I think its another part to help migrating Checkpoint configs to Fortigate. For example, the reason why Fortinet built the " any" Interface is the same.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors