There is an email server located outside our network that was running port 25 but is now running port 1234 instead. (example not real port).
We need to edit all email clients to the new port 1234.
Can the forti IOS redirect outbound port 25 dest address 1.2.3.4 to new port 1234 address 1.2.3.4?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hmm, I don't personally think so but I may be wrong. I have never heard of anyone doing something in that manner. I know PAT occurs but it isn't as cut and dry as you are saying.
Mike Pruett
Yes, you can do that definitely.
What you need is destination NAT with port forwarding, and the object doing this is a VIP (virtual IP). Define it on the 'internal' port. In order to activate the NAT, create a policy from 'internal' to 'wan' with destination address == VIP.
You can always check what is happening with 'diag debug flow'. NAT should be evident in the diag output.
Ede you rock! Learned something new today. Never thought of using the VIP to do it.
Mike Pruett
Glad I could help.
I had once combined VIPs with short names on the internal DNS zone, to make my life easier in connecting to customer firewalls.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.