Hello,
The context is a firewall policy to an SD-WAN zone.
Basic details: SD-WAN zone has two interface members: wan1 and GRE_Tun_0.
Is there any way for the policy to selectively NAT, depending on which zone interface gets used?
Example: traffic to wan1 must NAT but traffic to GRE_Tun_0 must not NAT?
Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Thank you for your question. In older versions of FortiOS, you could select each SDWAN member individually in firewall policy and that could be used for this.
In newer versions, only option is to create 2 different SDWAN zones. One for wan1, second for GRE tunnel. Then you can have 2 firewall policies, for each zone, where you can enable/disable NAT based on your requirements.
Hello and thanks for the feedback.
I didn't think of that but yeah, interesting idea to try. I'm testing how it works with Central NAT and that seems to do the trick as well...
Hello,
Central NAT also work, I didn't think about that. Good idea.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.