Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ralph1973
Contributor

fortigate ' listen' on ip subnet without having an interface

Hello, Hopefully can someone help. I have a vdom where traffic enters to let' s say 150.150.150.0/24 these addresses need to be translated to the 10.0.10.0/24 subnet, which lives on the interface in this vdom. How can I accomplish that? This vdom thus must listen to the 150.15.150.0 traffic without having an interface in that network. It only has an interface for the translated traffic. The traffic enters through a vlink which connects to a customer vdom. Thanks, Ralph
3 REPLIES 3
emnoc
Esteemed Contributor III

Can you draw map so we can get a clear idea of what your talking about. Provide interfaces and layer3 interfaces address. But I believe you need to look at SNAT with ip-pools

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Ralph1973
Contributor

Hello Emnoc, thanks for your reply! Attached is a drawing (with fictive addresses) that depicts an example traffic flow from one of the hundred hosts to one of the several servers; A Host (Host A) from CustomerA network needs to talk to the ACM server and traverses 2 Vdoms. Same for Host B which belongs to Customer B network and VdomB When Host A at 1.2.3.4 wants to connect to ACMserver at 10.65.16.71, the HostA uses destination 147.17.1.1 and the flow is like this: it' s source ip (1.2.3.4) is translated at VdomA to source ip 10.65.26.4 . Then the packet travels over the vdom link to the APP vdom which translates the destination address 147.17.1.1 to the ACMserver real adres 10.65.16.71 and after that send the packet over the interface (which belongs to the 10.65.16.0/24 network) to the ACMserver Question is: how can we process the incoming traffic (which has a destination 147.17.1.1) at the APPvdom , while this address has no interface associated with it. Only after translation, it can be send over an interface at that Vdom. So how can I make this APP vdom listen /respond to packets in the 147.17.1.0 network and then translate it to the appropriate network? thanks and regards,
netmin
Contributor II

Maybe a VIP on interface ' Any' could work for you (plus policy of course) :
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors