Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

SDWAN with NAT

FGT-A have 2 different link to FGT-B, 1st link must enable the NAT and the 2nd link not use NAT.

How we can create policy to enable NAT only for 1st link, since in the firewall policy we use sdwan interface for the destination?

3 REPLIES 3
johnathan
Staff
Staff

This article covers your scenario: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-one-certain-IP-pool-per-a-SD-WA...

"Never trust a computer you can't throw out a window."
HS08

But the link should be natted and use ip from the provider. 

With this condition what should i put in start and end ip addr?

sulanmu7
New Contributor

Your DNATs (VIPs) must be assigned to a specific interface. You can't select an SD-WAN zone, but you can specify "any" as the source interface, then this VIP won't be associated only with a specific wan interface.

https://19216811.cam/ https://1921681001.id/
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors