Hi guys,
What is the right procedure when creating NAT to my web server. should be accessible outside using a public ip of the same subnet as my wan interface. i am using sd-wan interface. thank you in advance.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
DNAT on Fortigate is configured using Virtual IPs. It's exactly the same with or without SDWAN.
See the below documentation for more details:
https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/728694/destination-nat
Yes you need a firewall policy, like this:
DNAT on Fortigate is configured using Virtual IPs. It's exactly the same with or without SDWAN.
See the below documentation for more details:
https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/728694/destination-nat
Sorry for the late response, got busy with other matters. Once i have configured the virtual ip, do i need to create a firewall policy?
VIP setup
Type: Static Nat
External IP: Wan1 public ip(i have other static ip aside from what is set on wan1 interface)
Map to: Local test server
I have searched for DNAT procedures online and they created firewall policy as well.
Yes you need a firewall policy, like this:
Thanks for the quick response. I am using sd-wan interface with 2 ISPs as member. Will it still work if i setup like below:
Sure it will.
Thank you.
Hi @kish02
When configuring DNAT, you can either use the WAN interface's IP or use another public IP (if your ISP has provided you with extra public IP addresses).
Hi @kish02,
Please refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Virtual-IP-VIP-port-forwarding-configurati...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.