I have a Fortigate firewall. The management IP block is 172.16.1.1/24.
Fortianalyzer(172.16.1.10) is in this range.. I have an SMTP server, and only the IP address 192.168.1.100 is allowed to access it. I can access the SMTP server by NAT my 172.16.1.10 server. However, I cannot access the SMTP server using the Fortigate management interface (172.16.1.1). NAT is not working.
Solved! Go to Solution.
try adding this ip either as a secondary on a existing interface in root vdom or create a loopback and assign it that IP and see if that works.
hi,
i think you can set the source ip from cli for smtp, https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-alert-email-settings/ta-p...
I entered the management interface IP address as the source IP. I also added the NAT rule, but it still isn't NAT.
Created on 11-01-2025 02:58 AM Edited on 11-01-2025 02:59 AM
local originating traffic from the FGT isnt subject to NAT, only for traffic passing through.
just try to enter as source the IP that is allowed on the remote SMTP, see if it works.
I'm trying this, but it's not accepting it because it's not in the root vdom.
this .
try adding this ip either as a secondary on a existing interface in root vdom or create a loopback and assign it that IP and see if that works.
I provided the IP address for the second IP. After that, I also provided this IP address to the source IP address. It is fixed for now.
The error means the IP you’re trying to use isn’t assigned to any interface in the root VDOM. You’ll need to use an IP that actually belongs to an interface in that VDOM, or create a loopback and assign it there first.
| User | Count | 
|---|---|
| 2727 | |
| 1416 | |
| 810 | |
| 738 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.