Hi
We have 2 internet links. The wan1 is connected to a mikrotik antenna and has following configuration:
Wan1 (port2)
IP address: 1.1.1.1/29 (valid ip)
Secondary ip: 172 10.20.2/30 (connected to antenna port)
Wan2 (port3)
Ip address: 2.2.2.2/24 (valid ip)
Secondary ip: 192.168.111.3 /30 (connected to LTE modem port)
SDWAN
wan1 --->default gateway-->172.10.20.1
wan2-->default gateway--> 2.2.2.1
The SDWAN is configured and it is working fine. Wan 1 is prefrred link and it will failover to wan2 in case of failure.
When wan1 is active, i can not ping ip or domain inside fortigate and i should use wan1 valid ip as source in order to ping. And also in firewall policy, i should select use dynamic ip pool and select an ip pool i created for wan1 valid ip, in order for SNAT to work. It does not work if i select use interface ip address. My question is that, if wan1 fails, wan2 become active and all SNAT rules won't work and i should manually set them to use interface address. How can i solve this problem?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Reza
You cas use Central SNAT, so you can add separate NAT rules for each wan port. So wan1 will NAT with IP pool, while wan2 can NAT with interface address.
Hi aek,
Thank you. Can you please explain more about central nat on my situation?
- I have so many SNAT and DNAT rules in firewall policy, if i enable CNAT, will all my rules stop working?
- why valid ip which i set on my wan1 port does not work directly?
Hi Reza
Yes all your NAT config will be erased when you enable central SNAT, but I think this should not impact your DNAT config (please double check). So you need to do it in off hours.
Your IP pool can't be valid with 2 wan interfaces if they are on different subnets.
For your valid IP please explain more and share design if possible.
Thanks. If i enable central nat can i choose wan1 to use ip pool and wan2 to use interface address? And if wan1 in sdwan fails, there will be no problem? Right?
- i have security profiles enables for snat, what will happen to them?
Yes that's right.
- nothing will change for security profiles.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.