Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

SD WAN Problem with 2 access One with NAT and one without NAT

Hi,

 

how can we configure this situation. We have a SD Wan with normal internet access A (1GB/1GB) with NAT router before the FG. The other interface is B MPLS and we dont have NAT.

 

Today A failed and users didnt have access to the internet but dod have access to the MPLS network. The SASE policy had NAT activated and so the access via B MPLS access dondt work. Cloning the same policy without NAT and pushing above solved the problem. Now with access A working again (preferred by SD WAN rule for internet access), users again could not access to the internet because of the policy above with NAT.

 

What can we do? I would like both options to work without having to change the policies.

 

Thanks!

3 REPLIES 3
funkylicious
SuperUser
SuperUser

hi, can you post the routing table on the FGT for SD-WAN members ? 

"jack of all trades, master of none"
"jack of all trades, master of none"
RolandBaumgaertner72
Contributor III

Hi,

 

I just tried again and with NAT on both policies it is working. Thing is, traffic over MPLS Access B is going over our central FG with also NAT policy. Now I tried from here, disabling Access A so that all traffic goes over MPLS B and before that I created a Policy on the Central FW without NAT and with the IP of the MPLS Router -> This would not work, though I see traffic in the policy from the MPLS Router. Activating NAT on this policy would work and I had access to www with this policy. So with that, this extra policy makes no sense since we have a general one with all branches, I only had to add the MPLS Router for source (policy with NAT) and it works fine.

 

Now I dont get it, NAT on the local and NAT on the central -> should not really work, no? Just because the Central FG knows the networks and routes it back? What would be best case scenario here?

 

Thanks!

AEK
SuperUser
SuperUser

For such situation Central SNAT is one of the possible solutions. 

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors