FortiGate has two NAT directions. Source NAT (SNAT) rewrites the source address of outbound traffic, while Destination NAT — called a Virtual IP (VIP) here — forwards inbound traffic to an internal server.
- Use Outgoing Interface Address — the simplest SNAT: everyone exits with the WAN interface IP.
- IP Pool — a range of public addresses; useful when a server needs a fixed outbound address.
- VIP — maps a public IP (and port) to an internal one, then is permitted by its own policy.
Top: SNAT for outbound traffic — the private source address is replaced by the wan1 address or an IP pool address. Middle: DNAT via a VIP object for inbound traffic — the external address maps to the internal server, and the policy destination must be the VIP object, not the private IP. Bottom: Policy NAT (configured inside each policy) versus Central NAT (one shared table), plus PAT where many hosts share one public IP separated by source port.