Dear all,
I have some case in Fortigate 100E like down bellow (Please see attachment):
Example IP 192.168.40.250 (NAT IP: 11.17.59.36) going to server ADPI (IP: 11.17.57.129)
They must going to gateway (IP:192.168.40.229) then go to IP gateway 11.17.59.33
After that when the link down, another link will up to lintas (IP: 202.152.42.161).
My question is ,in firewall, after the IP arrived in Fortigate (IP:192.168.40.229),
is the fortigate will read the NAT first (Server ADPI must use NAT IP) then the routing?
or the routing first then nat?
Because we make routing --> 0.0.0.0/0 --> 202.152.42.161, if the forti read the routing
first, we can not reach Server ADPI in that time
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Direct answer would be in the diagram. SNAT is applied after routing decides which interface to go out.
But when the link goes down, which is tied to 11.17.59.32/27, the another provider wouldn't routed packets back to your FGT but route to the original provider over the internet between two providers. So it wouldn't work any way. In other words, if the link from the original provider is down, the /27 is down as well.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1643 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.