Hot!NAT same port to Different internal IP addresses

Author
moelharrak
New Member
  • Total Posts : 5
  • Scores: -2
  • Reward points: 0
  • Joined: 2020/10/24 03:15:58
  • Status: offline
2020/10/24 03:26:21 (permalink) 6.2
0

NAT same port to Different internal IP addresses

Hi,
Is it possible on Fortigate to use the same port and NAT it to two different internal Devices depend to the which source public IP is requesting the connection?
Example :
     Src-IP-1 + DST-Port-222 --> 192.168.1.100:222
     Src-IP-2 + DST-Port-222 --> 192.168.1.101:222
 
Thank you
#1

1 Reply Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 2335
    • Scores: 227
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: NAT same port to Different internal IP addresses 2020/10/24 10:03:47 (permalink)
    5 (1)
    Yes, there is an option in VIP config to specify traffic by source IP(s). At least my 50E took the config below although I haven't test it.
     
    config firewall vip
        edit "VIPtest1"
            set src-filter "1.1.1.1"
            set service "SMTP"
            set extip x.x.x.x
            set extintf "WAN_INTERFACE"
            set portforward enable
            set mappedip "172.16.2.200"
            set mappedport 25
        next
        edit "VIPtest2"
            set src-filter "2.2.2.2"
            set service "SMTP"
            set extip x.x.x.x
            set extintf "WAN_INTERFACE"
            set portforward enable
            set mappedip "172.16.2.201"
            set mappedport 25
        next
    end


    #2
    Jump to:
    © 2020 APG vNext Commercial Version 5.5