Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor

Source Nat to the LAN IP ADDRESS


I have created the VPN IPSEC with my client. The destination address is only available from the fortigate local address (also in the configuration VPN IPSEC tunnel).


I need help how i can configure policy from another LAN address example to nat to the address gateway

Current policy:

edit 20 set uuid dfa6f7ae-dc73-51e5-66ad-f9a3bae3a82a set srcintf "LAN"  set dstintf "LAN" ( set srcaddr "tdu" ( set dstaddr "PBG_WIN" (IP addres set action accept set schedule "always" set service "ALL" set natip set nat enable

Bellow ip traffic from debug: fg # id=20085 trace_id=42 func=print_pkt_detail line=4471 msg="vd-root received a packet(proto=1,> from LAN. code=8, type=0, id=17638, seq=621." id=20085 trace_id=42 func=init_ip_session_common line=4622 msg="allocate a new session-00091d06" id=20085 trace_id=42 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw- via VPN_PBG" id=20085 trace_id=42 func=fw_forward_handler line=550 msg="Denied by forward policy check (policy 0)"

Traffic from is not nat to the address

From i can ping address, from i cannot do that, because policy is no nat this ip to the gateway address.

Please I need help


Try this:

For traffic from LAN to the .200 network this traffic needs to be sent down the tunnel. Thus, you need a policy from LAN to VPN_PBG. Source address (your LAN), destination address (remote LAN), action ACCEPT, NAT enable, specify IP pool "myLAN_tunnel_end".

In advance create an IP pool "myLAN_tunnel_end" with starting address, end address This will NAT any source address to the .1 address which is allowed across the tunnel.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Top Kudoed Authors