Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rcpdkc
Contributor III

Fortigate Gateway NAT Problem

I have a Fortigate firewall. The management IP block is 172.16.1.1/24.

Fortianalyzer(172.16.1.10) is in this range.. I have an SMTP server, and only the IP address 192.168.1.100 is allowed to access it. I can access the SMTP server by NAT my 172.16.1.10 server. However, I cannot access the SMTP server using the Fortigate management interface (172.16.1.1). NAT is not working.

1 Solution
funkylicious

try adding this ip either as a secondary on a existing interface in root vdom or create a loopback and assign it that IP and see if that works.

"jack of all trades, master of none"

View solution in original post

"jack of all trades, master of none"
8 REPLIES 8
funkylicious
SuperUser
SuperUser

hi,

i think you can set the source ip from cli for smtp, https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-alert-email-settings/ta-p...

"jack of all trades, master of none"
"jack of all trades, master of none"
rcpdkc

I entered the management interface IP address as the source IP. I also added the NAT rule, but it still isn't NAT.

funkylicious

local originating traffic from the FGT isnt subject to NAT, only for traffic passing through.

just try to enter as source the IP that is allowed on the remote SMTP, see if it works.

"jack of all trades, master of none"
"jack of all trades, master of none"
rcpdkc

I'm trying this, but it's not accepting it because it's not in the root vdom.

rcpdkc
Contributor III

this .fwww.png

funkylicious

try adding this ip either as a secondary on a existing interface in root vdom or create a loopback and assign it that IP and see if that works.

"jack of all trades, master of none"
"jack of all trades, master of none"
rcpdkc

I provided the IP address for the second IP. After that, I also provided this IP address to the source IP address. It is fixed for now.

ElwinBERRAR
New Contributor

The error means the IP you’re trying to use isn’t assigned to any interface in the root VDOM. You’ll need to use an IP that actually belongs to an interface in that VDOM, or create a loopback and assign it there first.

Elwin
Elwin
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors