Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sims
New Contributor III

NAT BASIC

Hi , I have the following Nat enabled policy Incoming interface is 10.1.1.1/24 Outgoing interface ip 4.4.4.4/24 And route  to  destination 8.8.8.8  via  gateway 10.1.1.1   If I ping 8.8.8.8 from source 10.2.2.2/24 . What will be the source ip? What if I ping 10.1.1.1 , the host 8.8.8.8 will reply? Thanks
1 Solution
Toshi_Esumi
Esteemed Contributor III

NAT works only for through traffic that would match the policy. Pining the interface coming from the same interface wouldn't hit the policy. It's called "local-in" traffic. The source wouldn't change in the reply packets.

View solution in original post

3 REPLIES 3
Toshi_Esumi
Esteemed Contributor III

If your default route (unless you have more specific route for 8.8.8.8) is pointing toward the outgoing interface, it would be SNATed with 4.4.4.4. That's what 8.8.8.8 side sees in the ping packet source IP, then where it would reply to.

If you run sniffer like "diag sniffer packet any 'host 8.8.8.8' 4", you would see those address changes at the NAT.

sims
New Contributor III

Hi,

What if i ping the incoming interface , there will be any translation 

Thanks  

Toshi_Esumi
Esteemed Contributor III

NAT works only for through traffic that would match the policy. Pining the interface coming from the same interface wouldn't hit the policy. It's called "local-in" traffic. The source wouldn't change in the reply packets.

Labels
Top Kudoed Authors