Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smaikol
New Contributor

Static routing NAT and Virtual IP

Hi all, i' m dealing with a configuration on a Fortigate 3108 NGFW and i have a problem i need to address or solve as quick as possible. Firmware version 5.X We use the FG as the Layer 3 routing for a site with multiple VLANs and there is also a poitn-to-point link to another FG on another site for DR. We need to do NAT rules like this, for DNS service all requests to ip 192.168.10.10 are natted to 192.168.30.10 that is another internal subnet. With the virtual ip feature this is quiet simple BUT the problem is that we also need to do a static route to the same IP , 192.168.10.10 to the other FG on the other site and this rule is never matched because virtual ip take precedence. The rule is not for the same protocol DNS, it' s for Domain Controllers. My question is, how is it possible to solve this? Is it possible to NAT this way without virtual IP? How eventually can i make the static route take precedence over virtual ip? Thanks in advance to all that can help to address this problem. smaikol
3 REPLIES 3
Maik
New Contributor II

as a start, please study the " Life of a Packet" documentation http://docs-legacy.fortinet.com/fos50hlp/50/index.html#page/FortiOS%25205.0%2520Help/life_of_packet.170.11.html
metturarun
New Contributor

Hi all, I too have same issue. I use Fortinet 40 C. We want to allow some internal server to external access. I have done the following . But still not able to access. 1) Created virtual IP and mapped external port 8086 and Internal port 8086 2) Added in firewall policy , allow src wan1 and dst internal ( local n/w) Can you please help me ? I am new to Fortinet. Thanks
Christopher_McMullan

From the sounds of it... Could you create a static route for a host mask, i.e., destination 192.168.10.10/32 via P2P link. In that case, you could create a central NAT table based on a variety of factors.

Regards, Chris McMullan Fortinet Ottawa

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors