Hoping someone can point me in the right direction to discover how outbound NAT can be applied in an SD-WAN configuration. Running 6.0.6
We have WAN1 and WAN2 in the SD-WAN interface. Both have /29 addresses. I need the Exchange server to use the 2nd available host address on the WAN interfaces for Outbound. But the WAN interfaces are not available options for destination interfaces, only the SD-WAN interface.
Is there a way to accomplish this that I am just not seeing?
Thanks,
The firewall policy's destination should be the SD-WAN interface. It's an SD-WAN rule that can specify which physical interface in the zone to go out for specific traffic like a source IP on the exchange server. Just choose "Manual" then specify the WAN interface the traffic needs to go out in "Outgoing Interfaces" section.
Toshi
You can try using ippool with the 'associated-interface'.
Refer to this link:
https://docs.fortinet.com/document/fortigate/6.0.0/cli-reference/438955/firewall-ippool-ippool6
I hope this helps.
best regards,
| User | Count |
|---|---|
| 2750 | |
| 1419 | |
| 812 | |
| 740 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.