Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
johnlloyd_13
Contributor II

FGT VIP and Firewall Policy Order

hi,

i'm going to configure a new FGT.

is it preferred to put/configure ALL VIP/DNAT rules on top then put ALL FW policy/SNAT afterwards?

can someone advise what's the best practice in FGT?

6 REPLIES 6
kmohan
Staff
Staff

Hello John

For VIP configuration, you can follow below kb articles:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Virtual-IP-VIP-port-forwarding-configurati...

Karthick
srajeswaran
Staff
Staff

Fortigate performs Destination NAT lookup first then do a policy match and then only source NAT rules comes in to picture, so ideally the order based on the DNAT/SNAT based policies are not going to make any difference.

You may place the policies that is expected to have high number of hits on top , this can help in scenarios where a session re-validation is required.

Below document explains the packet flow in FGT.
https://docs.fortinet.com/document/fortigate/6.4.0/parallel-path-processing-life-of-a-packet/86811/p...

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
johnlloyd_13
Contributor II

hi,

thanks for your responses! appreciate it.

one last question, if i got 2x interfaces (using private IP) in FGT that would need to communicate, do i just create 2x FW policy (only allowing specific service, i.e. 443, 53, icmp): one outbound and one inbound WITHOUT NAT?

i.e, port 1: 192.168.1.0/24 <> FGT <> port 2: 172.16.1.0/24

srajeswaran

Ideally creating policy without NAT is expected to work (assuming FGT is the gateway for these 2 subnets). If the gateway is different you need to enable source NAT.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
johnlloyd_13

hi,

yes, the FGT (interface IP) is the default GW for these 2x private subnets.

just to confirm, i'll need to create 2x FW policy for inbound and outbound traffic correct?

srajeswaran

Thats correct

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors