hi,
and welcome to the forums.
Yes, the VIP/destination NAT which you use to publish your internal servers is stateful. Even if not, FortiOS would always try to lead return traffic back to the port it came in.
You need to have appropriate routes (that is, 2 equal default routes) in place, and of course policies allowing the traffic in.
Incoming traffic (NATted or not) will create a session if allowed. Part of the session state is the ingress port. FortiOS will try to send return traffic via the same (ingress) port.
So far the theory. As I have not got a dual-WAN setup at the moment I cannot confirm this. You will need two default routes in any case, with equal distances, otherwise ingress traffic may be dropped.
Maybe other forum members could comment on this, as seen in practice.
Besides, Fortigates regularly don't allow a session packet coming in one side and a return packet going back on the other side as "asymmetric route" unless you specifically configured to allow it.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1787 | |
1117 | |
768 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.