Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smilings
New Contributor

Creating a NAT in Fortigate 120G

Currently we have a Cisco Firewall that has multiple NAT rules for Citrix applications. Now we are adding a Fortigate FW in front of the Cisco Firewall and it blocks Citrix applications. Do I need to create the same NAT rules on the Fortigate FW or could I create a range to allow all the NAT rules through the Fortigate. What would you suggest?

 

NAT Rules Fortinet.png

1 REPLY 1
ede_pfau
SuperUser
SuperUser

Hello,

and welcome to the forums.

Depends on the NAT rules. I assume they translate the WAN IP to some internal address, and if you put a FGT in front, the WAN address remains with the FGT and all addresses behind it will be of private networks.

Works as designed.

If you absolutely do not want to rewrite your NAT rules (which would be the straightforward solution), maybe you could deploy the FGT in Transparent mode. Basically, the FGT will act like a Layer 2 device, bear no IP addresses and will not route.

I once had a situation where I had to protect a weak (competitor's) firewall quickly, and put a TP mode FGT in front. No changes to the protected network at all, high rate of blocking attacks, happy customer.

 

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors