Currently we have a Cisco Firewall that has multiple NAT rules for Citrix applications. Now we are adding a Fortigate FW in front of the Cisco Firewall and it blocks Citrix applications. Do I need to create the same NAT rules on the Fortigate FW or could I create a range to allow all the NAT rules through the Fortigate. What would you suggest?
Hello,
and welcome to the forums.
Depends on the NAT rules. I assume they translate the WAN IP to some internal address, and if you put a FGT in front, the WAN address remains with the FGT and all addresses behind it will be of private networks.
Works as designed.
If you absolutely do not want to rewrite your NAT rules (which would be the straightforward solution), maybe you could deploy the FGT in Transparent mode. Basically, the FGT will act like a Layer 2 device, bear no IP addresses and will not route.
I once had a situation where I had to protect a weak (competitor's) firewall quickly, and put a TP mode FGT in front. No changes to the protected network at all, high rate of blocking attacks, happy customer.
| User | Count |
|---|---|
| 2737 | |
| 1418 | |
| 812 | |
| 739 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.