Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tedd
New Contributor

Nat in transparent mode

Hello everyone !

 

Pic below is the network infrastructure,we are going to install Fortigate in transparent mode. the only issue is:  a device in the network is accessed with IP 192.168.100.101 but actually IP is 192.168.100.199. we need to add an one to one NAT rule.

Refers to knowledge Base:

https://help.fortinet.com...Transparent%20Mode.htm

 

https://kb.fortinet.com/k...nk.do?externalID=12086

 

Said that it is possible to configure NAT in transparent mode, however, with the restricted environment, change device IP or add another IP sagement is forbidden. Is there any configure we miss or new version FortiOS allow to run NAT in transparent mode with same IP segement ?

 

 

 

Best regards,

Keep The Faith !!
Keep The Faith !!
1 REPLY 1
ede_pfau
Esteemed Contributor III

hi,

 

both KB articles refer to source NAT. In your case, you are looking to create destination NAT.

I haven't used Transparent mode much but just go ahead and create a VIP, translating .101 into .199, and a policy from LAN to LAN, source ALL, dest your_VIP.

When testing, notice that you can only use ping if the VIP is not port-translating (as ping/ICMP does not use ports).


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors