We have switched from Sophos UTM to Fortigate and we used to have DNAT rules to redirect all internal traffic to any destination with specific service to secific internal IP.
scr.ip ANY > dst.ip ANY > dst.port tcp-udp/123 > dst.ip 10.20.30.40 > dst.port tcp-udp/123
src.ip ANY > dst.ip ANY > dst.port udp/53 > dst.ip 10.20.30.50 > dst.port tcp-udp/123
I only can find DNAT via Virtual IP - but there is no option to create rules like above.
Can anyone help me out or open my eyes to find the way to go.
Thx and greetings
Christian
Try add VIP as follows:
And add firewall rule as follows:
Hope it helps.
This was my first attempt. But Forti will not allow this for Ext Int.
0.0.0.0 --> error: IP must not be zero
0.0.0.0/0 --> error: Invalid IP Range
0.0.0.0-255.255.255.255 --> error: IP must not be zero & IP range too large for mapped IPs
Which FortiOS are you using?
On my 7.0.17 I can specify 0.0.0.0 as external IP.
Created on 06-29-2025 12:03 AM Edited on 06-29-2025 12:04 AM
We are using 7.4.8
And your screen shows exactly, what i wish to do.
Even on CLI we can't do it.
Our Service Provider don't know, why anybody would like to do this... :(
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.