FortiGate Central NAT Must Be Configured Before Building Firewall Policies
When migrating firewall policies to FortiGate from Cisco ASA or Palo Alto, administrators must decide between central NAT and per-policy NAT before writing any rules, as FortiOS does not allow switching modes once policies referencing VIPs or IP pools exist. Per-policy NAT is the FortiGate default, but it poorly mirrors the separate NAT table structure used by ASA and PAN-OS, often requiring duplicate translation entries across many policies. Central NAT more closely replicates the source architecture, using a single ordered SNAT and DNAT table independent of firewall allow/deny rules. Attempting to enable central NAT on a box with existing VIP or IP pool references will fail with an error, forcing administrators to dereference every such object before the mode toggle is accepted. Additionally, central NAT changes how destination addresses must be written in policies — rules must reference the internal mapped address rather than the public VIP address, a distinction that can cause hard-to-diagnose failures during cutover.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in