HI!
Does anybody know if exist the possibility of configuring and controlling central SNAT using the destination port? I mean, could you make the firewall SNAT HTTPS traffic and not SSH traffic, for example?
I think that it is not possible, in the version I am using, 6.0.13, but I would like to check if it is as I expect.
Thanks for support!
Hey Unai,
as far as I can tell, SNAT can only be set according to source port and IP protocol (TCP/UDP/ICMP/etc), but not destination port or service, even in newer versions.
The only way I have been able to find is with different policies with different NAT settings (no central NAT)
-> policy 1 applies to HTTPS, NATs to pool1
-> policy2 applies to SSH, NATs to pool2
Hey debbie,
It is as I thought, it is a big problem not to control the SNAT using the service or destination port.
Hey Unai,
I'm sorry I didn't have better news for you. You can reach out to your local Sales representative for a feature request, to have the option of destination port/services added to central SNAT.
I checked that this is possible in the 7.0.x version, but upgrading to that version is not a option for us
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.