Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smartgate
New Contributor

SNAT for two ISP routes on Fortigate

스크린샷 2024-01-31 112659.png

hello
We are trying to obtain two ISP lines by adding a new ISP line to the existing single ISP line configuration.
I don't know yet whether these two will be configured as active-active or active-standby.
SNAT is required for both lines, and in the case of Active-Active, two IP pools will be applied to the policy to enable sequential NAT processing.
However, when operating as active-standby, I do not know how to switch the SNAT IP in the firewall when switching lines.
If you have experience or know anything about this situation, please help.

 

2 REPLIES 2
AEK
SuperUser
SuperUser

Hello

For such situation I prefer combine SD-WAN with Central SNAT.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-and-configure-central-SNAT/ta-p/202...

AEK
AEK
hbac
Staff
Staff

Hi @smartgate,

 

FortiGate will SNAT the traffic to ISP1 or ISP2 IP address based on outgoing interface. You don't have to switch the SNAT IP in the firewall when switching lines. The FortiGate will do it for you.

 

If you are using SDWAN, please make sure to configure performance SLA to update the static route in case the ISP is down.

 

If you are not using SDWAN, you can configure link-monitor to update the static route. 

 

Regards, 

Labels
Top Kudoed Authors