Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dtap
New Contributor

Fortigate in Azure triple-NAT

I just setup a Fortigate NGFW in a VM in Azure, but I realized I would be adding 2 additional layers of NAT in front of my load-balaced web servers. Meaning, now (ELP=External Load Balancer;PIP=Public IP; ILB=Internal Load Balancer): ELB PIP --->(NAT)---> VM internal IP with firewall: Firewall PIP --->(NAT)---FW internal IP--->(NAT)---ILB--->(NAT)---VM internal IP

I don't think triple NAT can be considered an optimal setup. Am I just doing this wrong?

 
1 REPLY 1
emnoc
Esteemed Contributor III

It's not ideal but something it's the law of the jungle and you have no other options. Ideally you want  NAT simplified but even in AWS with EIP, you have the same issues sometimes.

 

It make gathering logging and details about session flow harder to track also.

 

 

ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors