Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MED-90
New Contributor

migrate from Palo Alto firewall to Fortigate

Hello .I have a project to migrate from Palo Alto firewall to Fortigate. Unfortunately, we don’t have the FortiConverter tool, so I proceeded to migrate the configuration manually. I have a problem with some NAT rules and need your help.

X.jpgY.jpgZ.jpg

5 REPLIES 5
MED-90
New Contributor

Your help please, is it a source NAT or a destination NAT?

AlexC-FTNT
Staff
Staff

No idea how to convert this, but there are a couple of keywords I guess they hint on the direction:

 

<destination> DSI_F5 <service>HTTPS >> so this is pushed to a F5 load balancer IP (=looks like DNAT to me)

<to> INTERNET // <source> local IP >> this is the reverse direction (=SNAT). The SNAT is done automatically in FortiGate for the VIP addresses

<bidirectional> -- > yes (confirmation of the above)

 

The log image part (right side) looks more clear. Gives the destination address (on PA) and the NAT IP of the server (DNAT)


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
MED-90

 So the configuration on Fortigate should be like this, is that correct?forti-nat.jpg

AlexC-FTNT

Looks right Mede (not sure about the services) with one mention: proxy mode. And then you probably need another/reverse policy for the outgoing access (if these server/s need internet access - only NAT enabled). 


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
MED-90
New Contributor

Thank you for your help :)

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors