Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
peanut
New Contributor

Source Address after NAT wrong

Hi

 

I migrated over to my HA Fortigate 100D setup from my Cisco Router.

 

What I have noticed is that with external requests going to my internal NAT server, is it is showing that the external connection is made from the VLAN interface IP address instead of the original external Source IP.

 

this is a bit frustrating because some Linux machines behind the fortigates are blacklisting the interface address due to failed hack attempts because it all seems to come from one address -- hope this makes sense.

 

so an external requests looks like its coming from the interface address 192.168.30.254 and not the original source public address of 41.xxx.xxx.xxx etc.

 

hope this is just me making a noob mistake on the new toys...

 

1 Solution
gschmitt
Valued Contributor

Go to Policy&Objects > IPv4 > Policies and look for your wan to VLAN/internal policy

Double click it

Set NAT to OFF

 

NAT or Network Address Translation literally takes the TCP/UDP package, changes the Source Address with a set (or the interfaces) IP address.

This is useful when going into external networks, i.e. when I access a website I want my NAT device to exchange my 192.168.1.1 IP with my external 88.77.66.55 IP or the webserver will ignore my request since 192.168.1.1 is a private IP and the package (martian package) literally can't find it's way back to me and will be discarded.

But on external > Internal policies it's best to leave it off, so the original IP will be transmitted.

View solution in original post

2 REPLIES 2
gschmitt
Valued Contributor

Go to Policy&Objects > IPv4 > Policies and look for your wan to VLAN/internal policy

Double click it

Set NAT to OFF

 

NAT or Network Address Translation literally takes the TCP/UDP package, changes the Source Address with a set (or the interfaces) IP address.

This is useful when going into external networks, i.e. when I access a website I want my NAT device to exchange my 192.168.1.1 IP with my external 88.77.66.55 IP or the webserver will ignore my request since 192.168.1.1 is a private IP and the package (martian package) literally can't find it's way back to me and will be discarded.

But on external > Internal policies it's best to leave it off, so the original IP will be transmitted.

peanut

thank you!!

 

knew it was something easy.

Labels
Top Kudoed Authors