One of the internal systems with IP 10.58.0.11 needs to access another remote network.
10.58.0.11 is internal to us Remote network is part of our organisation but geographically different.
10.58.0.11 is not routable to the remote network as they do not accept them. In this case, we will need to do an outbound NAT so session from 10.58.0.11 to the remote network gets translated to a range that they accept which is 10.82.0.x. Briefly, 10.58.0.11 needs to be translated outbound to one ip in 10.82.0.x so the remote site accepts it. I want to do this on fortinet firewall.Can someone please help how it should be done.
Appreciate all help.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
create an IP pool with the 10.82.0 addresses and use it in an SNAT policy like below.
The default rule is "overload" but you can change the ippool type to like one-to-one, etc. explained below:
Thank you, is there any way for me to verify if this is working from cli or gui?
Best way to confirm is "flow debug" or "debug flow" in below KB doc. If you read each line of output you can find the line swapping the source address from the local one to one of IPs in IP pool based on the rule you've chosen.
http://kb.fortinet.com/kb/viewContent.do?externalId=FD30038
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.