Hello Team,
I have requirement to migrate from ASA to FortiGate.
In FortiGate I'm using Policy based mode. and OS ver. 7.x
Below Two NAT statements on ASA (which is bidirectional).
nat (inside,outside) source static obj-192.168.1.1 obj-172.16.1.100
nat (inside,outside) source static obj-192.168.1.2 obj-172.16.1.100
I have to configure these NAT on FortiGate FW as it is without port forwarding using DNAT.
can anyone help me with that ?
Hi ALM13,
You can configure VIP to do the DNAT. Please make sure port forwarding is disabled, Kindly check below link:
https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/510402/static-virtual-ips
Regards,
Parteek
Hi Prateek,
I have tried this solution but didn't worked and the solution you provided that is applicable when Central NAT is Disable but in my case Central NAT is enabled and NAT should happen like below:
Ext IP: Mapped IP
172.16.1.100 192.168.1.1 and 192.168.1.2
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.