FGT-A have 2 different link to FGT-B, 1st link must enable the NAT and the 2nd link not use NAT.
How we can create policy to enable NAT only for 1st link, since in the firewall policy we use sdwan interface for the destination?
This article covers your scenario: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-one-certain-IP-pool-per-a-SD-WA...
But the link should be natted and use ip from the provider.
With this condition what should i put in start and end ip addr?
Your DNATs (VIPs) must be assigned to a specific interface. You can't select an SD-WAN zone, but you can specify "any" as the source interface, then this VIP won't be associated only with a specific wan interface.
User | Count |
---|---|
2559 | |
1356 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.