Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

Fortigate SNAT problem with SDWAN

Hi

We have 2 internet links. The wan1 is connected to a mikrotik antenna and has following configuration:

Wan1 (port2)

IP address: 1.1.1.1/29 (valid ip)

Secondary ip: 172 10.20.2/30 (connected to antenna port)

 

Wan2 (port3)

Ip address: 2.2.2.2/24 (valid ip)

Secondary ip: 192.168.111.3 /30 (connected to LTE modem port)

 

 

SDWAN

wan1 --->default gateway-->172.10.20.1

wan2-->default gateway--> 2.2.2.1

 

The SDWAN is configured and it is working fine. Wan 1 is prefrred link and it will failover to wan2 in case of failure.

 

When wan1 is active, i can not ping ip or domain inside fortigate and i should use wan1 valid ip as source in order to ping. And also in firewall policy, i should select use dynamic ip pool and select an ip pool i created for wan1 valid ip, in order for SNAT to work. It does not work if i select use interface ip address. My question is that, if wan1 fails, wan2 become active and all SNAT rules won't work and i should manually set them to use interface address. How can i solve this problem?

 

 

Reza F.
Reza F.
5 REPLIES 5
AEK
SuperUser
SuperUser

Hi Reza

You cas use Central SNAT, so you can add separate NAT rules for each wan port. So wan1 will NAT with IP pool, while wan2 can NAT with interface address.

AEK
AEK
rezafathi
Contributor II

Hi aek, 

Thank you. Can you please explain more about central nat on my situation?

 

- I have so many SNAT and DNAT rules in firewall policy, if i enable CNAT, will all my rules stop working?

 

- why valid ip which i set on my wan1 port does not work directly?

Reza F.
Reza F.
AEK

Hi Reza

Yes all your NAT config will be erased when you enable central SNAT, but I think this should not impact your DNAT config (please double check). So you need to do it in off hours.

Your IP pool can't be valid with 2 wan interfaces if they are on different subnets.

For your valid IP please explain more and share design if possible.

AEK
AEK
rezafathi
Contributor II

Thanks. If i enable central nat can i choose wan1 to use ip pool and wan2 to use interface address? And if wan1 in sdwan fails, there will be no problem? Right?

 

- i have security profiles enables for snat, what will happen to them?

Reza F.
Reza F.
AEK

Yes that's right.

- nothing will change for security profiles.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors