Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ShafBari
New Contributor

NAT exemption

Hi,

I have a FG-60-E-BDL to be configured for one of my customers. I need to know whether i can exempt the LAN traffic from NAT based on the destination. Its a flat network with a single Vlan and the internet traffic should go through the firewall with NAT while the traffic towards their branches should be exempted from the NAT.

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

It's just about FW policies you have and need to add. Does the branch traffic come/go through the same interface the internet traffic comes/goes through? Then you need to separate branch traffic by source and/or destination addresses/subnets in a new policy without NAT since the interface is the same.

sw2090
Honored Contributor

additional: mind the order of your policies! FGT Policies are first come first serve! 

So policies for the branches have to come first if they use the same source net and/or interface!

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors