Skip to main content
AD Academy
Network security: Fortinet
Intermediate15 minLast updated: Topic 5 of 14

NAT on FortiGate: SNAT and VIP

Outbound address translation, IP pools and publishing an internal server with a Virtual IP.

Not read

What you will learn here

  • How outbound NAT (SNAT) works
  • What an IP Pool is
  • How to publish a server with a VIP

Worth reading first:Firewall policies and objects

FortiGate has two NAT directions. Source NAT (SNAT) rewrites the source address of outbound traffic, while Destination NAT — called a Virtual IP (VIP) here — forwards inbound traffic to an internal server.

  • Use Outgoing Interface Address — the simplest SNAT: everyone exits with the WAN interface IP.
  • IP Pool — a range of public addresses; useful when a server needs a fixed outbound address.
  • VIP — maps a public IP (and port) to an internal one, then is permitted by its own policy.

Top: SNAT for outbound traffic — the private source address is replaced by the wan1 address or an IP pool address. Middle: DNAT via a VIP object for inbound traffic — the external address maps to the internal server, and the policy destination must be the VIP object, not the private IP. Bottom: Policy NAT (configured inside each policy) versus Central NAT (one shared table), plus PAT where many hosts share one public IP separated by source port.

Short and clear

  • SNAT is outbound: it rewrites the source address to the WAN IP or an IP pool address.
  • VIP is inbound: it maps a public address to an internal server (DNAT).
  • In an inbound policy the destination must be the VIP object, not the private IP.
  • Central NAT collects every NAT rule in one table instead of inside each policy.

Real-life examplePublishing a web server: create a VIP from 203.0.113.10:443 to 10.20.20.10:443, then a wan1 → dmz policy whose destination is that VIP and whose service is HTTPS.

config firewall vip
  edit "WEB-SERVER"
    set extip 203.0.113.10
    set extintf "wan1"
    set mappedip 10.10.10.20
    set portforward enable
    set extport 443
    set mappedport 443
  next
end
text

Check yourself

What goes in the Destination field of the policy allowing access through a VIP?

Was this page helpful?