Terme informatique

Central NAT FortiGate

A mode that separates the rules NAT Security Policy FortiGate.

⌚ About 2 min read
View my favorites

Central NAT on FortiGate The policy is based on the following principles: SNAT is searched in the Central-Skat table according to its criteria and order.

Simple definition

A mode that separates the rules NAT Security Policy FortiGate.

Technical definition

A mode that separates the rules NAT Security Policy FortiGate. In FortiOSThis concept is directly involved in the configuration of the firewall, routing, VPN or network security.

What is it used for?

Administer more properly a FortiGate and diagnose associated flows or services.

Practical example

Example: an administrator can encounter this concept when setting up a FortiGate site.

How to diagnose Central NAT FortiGate ?

Start by checking if Central mode NAT is actually enabled in system settings, then display rules Central1990T. For a given stream, raise source interface, destination interface, addresses and service, and then search for the first rule that matches. Then check the security policy separately: a correct translation does not mean that traffic is allowed.

  1. Drive Central Mode NAT.
  2. Identify the policy that allows the flow.
  3. Identify the corresponding Central-StaT rule.
  4. Compare the newspapers with the expected translated address.

Common issues

The most frequent errors are the order of rules, an interface or an overly broad address object, and confusion between policy and NAT. A Central1990T rule placed too high can translate traffic that was to use another address. Also avoid looking only for the option NAT in the policy when a FortiGate operates in Central mode NAT.

How to validate the correction — Central NAT FortiGate

After modification, test a specific flow and simultaneously control traffic logs and the source address seen on the destination side. If several rules can match, document their order before moving them. A proper validation must confirm three elements: the correct policy, the correct CentralSkaT rule and the translation actually observed on the traffic.

FAQ — Central NAT FortiGate

Central NAT Is it replacing the policies FortiGate ?

No. The policies continue to authorize or refuse traffic; Central NAT manages the translation separately.

Why is the order of rules important?

The first Central-Skat rule for the flow can determine the translation applied.

How to validate a correction?

Play a known stream, read the logs and check the source address actually presented at the destination.

♡ 0