Hi All,
I have a Forti 60D sitting behind a router.
The box is configured with LAN IP (e.g. 192.168.1.1/24) and secondary IP address (e.g. 10.18.18.2/28).
The router is at 10.18.18.1.
Currently in traceroute, the router is seeing 192.168.1.1 traffic as the source.
How to make the traffic to come out from the IP 10.18.18.2 as the source? is it possible on this box?
edit: Something came to mind, if the above is possible, would the change affect traffics coming from the 192.168.1.0/24 subnet? current ipv4 policy is NO NAT.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I have this constellation
there is several Roouters connected to my FortiGate for Internetaccess. Each is connected to one Port and that port and the router share a subnet. All Interfaces that are connected to routers for internet are members of sd-wan for load balancing.
The Policy for internet then is:
-incoming interface/address = where the traffic comes from
- outgoing interface = sdwan
- outgoing address = ANY
and then:
NAT enabled using the destination interface ip.
Since sdwan cares for the routing the packets will get NATed with the ip of the interface they have to go out to the internet. Works fine so far.
Instead of sdwan you could of course use a single wan too...
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hi,
You can specify the IP address you want to run the traceroutes from by running:
execute traceroute-options source 10.18.18.2
Hope that helped.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1702 | |
1092 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.