Hello,
Anybody know if it's possible to have NAT and UTM disabled by default when creating new IPV4 policy rules ?
Didn't found in documentation.
Thank you.
Alexandre.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If CLI nothing should be on: no NAT, no UTM, nothing.
If you create a new policy via GUI, it's probably depending on the version you're running. My 6.0.7 shows schedule=always, action=accept, NAT=on with interface IP, no security profiles, etc. Also some other GUI wizard automatically generates policies, like VPN wizard. Those would create them specifically match what needs to be created.
You should test it yourself with your FGT.
If you need to create a lot of policies with certain defaults, it's better to script it. Create the policies in text form and paste them into a SSH window, or submit as batch command.
IMHO NAT is only active per default if the destination interface is of type WAN...but I might be wishing it was.
I believe Ede is right, any WAN interface or interface with a default-route can have NAT enabled when you create the policy from gui.
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.