Hello,
The context is a firewall policy to an SD-WAN zone.
Basic details: SD-WAN zone has two interface members: wan1 and GRE_Tun_0.
Is there any way for the policy to selectively NAT, depending on which zone interface gets used?
Example: traffic to wan1 must NAT but traffic to GRE_Tun_0 must not NAT?
Thanks.
Hello,
Thank you for your question. In older versions of FortiOS, you could select each SDWAN member individually in firewall policy and that could be used for this.
In newer versions, only option is to create 2 different SDWAN zones. One for wan1, second for GRE tunnel. Then you can have 2 firewall policies, for each zone, where you can enable/disable NAT based on your requirements.
Hello and thanks for the feedback.
I didn't think of that but yeah, interesting idea to try. I'm testing how it works with Central NAT and that seems to do the trick as well...
Hello,
Central NAT also work, I didn't think about that. Good idea.
User | Count |
---|---|
2035 | |
1164 | |
770 | |
448 | |
327 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.