Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Howto NAT an internal SMTP server IP to outside!

I use a 50A with NAT Config and German DSL Connection. From my ISP i get an fixed IP 213.9.120.38 and a Subnet 213.9.58.128/29. I use a VIP to forward the SMTP traffic on 213.9.58.129 coming to my internal SMTP server on 192.168.1.3 (Static NAT with Portforwarding only on Port25). Works perfect. But when i send out emails the connecting IP is the 213.9.120.38. How should i create a Policy for translating the 192.168.1.3 to the 213.9.58.129 in the outgoing traffic?
7 REPLIES 7
Not applicable

Have you checked NAT in outgoing rule?
Not applicable

shure. but i have the problem, that whenever i create an outgoing rule with NATs the 192.168.1.3 to the 213.9.58.129 over VIP an IP-Adress conflict arises and my SMTP server detects another 192.168.1.3 Adress in the Net (because then an loopback seems to be createt) (the 192.168.1.3 is NATed to the 213.9.58.129 and back to the 192.168.1.3 but with the MAC of the external A50 Network). So i define the VIP with source 192.168.1.3, destination 0.0.0.0 and portforwarding on port 25 in the VIP. in the rule i define ALL services allow. But the rule is not shown in the Active Connections Status.
rwpatterson
Valued Contributor III

You should use an IP pool. Create a single IP pool, and use that dynamic IP pool in the rule. This will show outbound traffic for this policy to be coming from the IP address in the pool. -Bob

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

I dont understand how to use this feature. what ips should i use in the pool and what policy should i add?
rwpatterson
Valued Contributor III

The IP pool is the list of addresses you wish to ' show' the outside Internet world. When you open the policy for your outbound SMTP traffic, click the NAT check box. You will then be able to select ' Dynamic IP Pool' , which will translate all outgoing SMTP traffic for this policy to the list of IP addresses in the pool (one address). -Bob

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

create an ip pool with only the ip need to be used as external for the mailsrv (213.9.58.129) than create a firewall rule specific for the mailsrv. SRC LAN/192.168... DST WAN/all ACT Accept SRV Any NAT / Ip pool ( the name of the ip pool you have created before and go...) bye
Not applicable

tnx PMan, this does the job. tnx a lot!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors