Created on ‎01-17-2011 12:08 PM
The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
Source IP address and IP pool address matching When the source addresses are translated to the IP pool addresses, one of the following three cases may occur: Scenario 1: The number of source addresses equals that of IP pool addresses In this case, the FortiGate unit always matches the IP addressed one to one. (...)So if you define the original subnet and the mapped-to subnet to be equally sized then 1:1 matching ALWAYS occurs. Your setup of " overlapping VPN subnets" is not uncommon. There is a chapter on this as well: " Ch. 7" >" Gateway-to-gateway configurations" >How to work with overlapping subnets" (p.802 ff.). Just one hint: you do not only need source NAT (via ippool) but destination NAT as well (via VIP).
The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
User | Count |
---|---|
2539 | |
1352 | |
795 | |
642 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.