Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
FortiGate can perform NAT in two different ways: policy NAT, where source NAT is enabled directly in an IPv4 firewall policy, and Central NAT, where source translation is handled by a separate Central SNAT table. Destination NAT, including port forwarding, uses VIP objects.
The correct configuration depends on whether Central NAT is enabled. The instructions below use the FortiOS 7.6.5 and 7.6.6 interface paths. Before changing NAT, confirm the current mode and take a configuration backup.
Understand FortiGate NAT modes first
| Mode | Where source NAT is configured | Where destination NAT is configured |
|---|---|---|
| Policy NAT | Policy & Objects > Firewall Policy, using the policy’s NAT option | VIP selected in the firewall policy |
| Central NAT | Policy & Objects > Central SNAT | Separate VIP object under Policy & Objects > DNAT & Virtual IPs |
Central NAT is disabled by default in standard policy-based configurations. However, in policy-based NGFW mode, central SNAT is assumed to be enabled implicitly. Do not mix instructions from the two modes.
The most common configuration error is enabling NAT in a firewall policy while Central NAT is active. In that situation, the policy NAT option is skipped. The source translation must be defined in config firewall central-snat-map.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Configure outbound NAT with a firewall policy
Use policy NAT when Central NAT is disabled and internal clients need to access the Internet through the FortiGate’s outgoing interface address or an IP pool.
Using the GUI
- Go to Policy & Objects > Firewall Policy.
- Edit the IPv4 policy that allows traffic from the internal interface to the WAN interface, or select Create New.
- Set the incoming interface to the LAN or internal interface.
- Set the outgoing interface to the WAN interface.
- Choose the appropriate source address, destination address, schedule, and service.
- Enable NAT.
- For normal masquerading, select Use Outgoing Interface Address.
- For a fixed public address or address range, select an IP pool instead.
- Save the policy and place it above any broader policy that could match first.
The firewall policy must allow the traffic. NAT only changes the source address; it does not replace the security policy.
Policy NAT CLI example
config firewall policy
edit 12
set name "LAN-to-Internet"
set srcintf "lan"
set dstintf "wan1"
set srcaddr "all"
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
set nat enable
next
end
The important command is set nat enable. The policy ID, interfaces, address objects, and services must match your own configuration.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteEnable Central NAT
Central NAT moves source translation out of individual firewall policies and into a dedicated, ordered table.
Enable it in the GUI
- Go to System > Settings.
- Under System Operations Settings, enable Central SNAT.
- Click Apply.
After it is enabled, Central SNAT appears under Policy & Objects.
Enable it with the CLI
config system settings
set central-nat enable
end
To turn it off:
config system settings
set central-nat disable
end
Before switching modes, check whether any VIP is attached to a firewall policy. A VIP assigned to a policy in non-central mode must be unassigned before switching to Central NAT. The VIP object itself can remain available.
Configure outbound Central SNAT
Using the GUI
- Go to Policy & Objects > Central SNAT.
- Click Create New.
- Set the incoming interface to the internal interface.
- Set the outgoing interface to the WAN interface.
- Choose the source and destination address objects.
- Enable NAT.
- Under IP Pool Configuration, choose Use outgoing interface address for masquerading, or Use Dynamic IP Pool for a configured pool.
- Optionally restrict the rule by protocol, destination port, or source port.
- Enable the policy and save it.
Central SNAT rules are evaluated from top to bottom. FortiGate stops at the first matching rule, so put specific rules above general rules. For example, a rule for one server or destination port should be above a rule matching all internal addresses and all services.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #2
- Extensive Connectivity Options: The FortiGate 60F is designed with 10 GE RJ45 ports, including 2 WAN ports, 1 DMZ port, and 7 internal ports, offering broad flexibility and high-density connections for diverse enterprise networking needs.
- Superior Performance for Secure Networks: Features powerful system-on-a-chip acceleration to deliver top-tier security with 1.4 Gbps IPS throughput and 700 Mbps threat protection throughput, ensuring effective defense against advanced threats.
- Enhanced SSL Inspection and SD-WAN Capabilities: Utilizes purpose-built security processor technology to provide the industry's highest SSL inspection performance and robust SD-WAN functionality for secure, high-speed network operations.
- Simple and Effective Management: Comes equipped with a user-friendly management console that supports comprehensive network automation and visibility, alongside Zero Touch Integration with Fortinet's Security Fabric for streamlined deployment.
- Advanced Security Features: Leverages continuous threat intelligence from AI-powered FortiGuard Labs, identifying and mitigating both known and unknown threats, enhancing security across all network traffic, whether encrypted or not.
Central SNAT is applied after the security policy. A matching SNAT rule cannot make a denied session work.
Central SNAT CLI example
config firewall central-snat-map
edit 1
set status enable
set srcintf "lan"
set dstintf "wan1"
set orig-addr "LAN-subnets"
set dst-addr "all"
set nat enable
next
end
A more selective rule can include a protocol and destination port:
config firewall central-snat-map
edit 2
set status enable
set srcintf "lan"
set dstintf "wan1"
set orig-addr "app-server"
set dst-addr "all"
set protocol 6
set dst-port 443
set nat enable
set comments "HTTPS outbound translation"
next
end
Protocol number 6 represents TCP. Use the address objects and interface names that exist on your FortiGate.
Configure a dynamic IP pool
Use an IP pool when outbound sessions must use a particular public address or range instead of the WAN interface address.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →- Go to Policy & Objects > IP Pools.
- Click Create New.
- Enter the external IP address or range.
- Choose the appropriate pool type and save it.
- Select the pool in the policy NAT configuration or in the Central SNAT rule.
Explicit port mapping is supported only with an Overload IP pool. It is not available with every pool type.
Configure destination NAT and port forwarding
Destination NAT forwards an external address to an internal server. FortiGate implements this with a VIP, or virtual IP object.
Supported VIP types include static VIPs, static VIPs with services, static VIPs with port forwarding, FQDN-based VIPs, and virtual-server load balancing.
Rank #3
- INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
- UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
- IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
- CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
- COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.
Central NAT mode: create a VIP
- Go to Policy & Objects > DNAT & Virtual IPs.
- On the Virtual IP tab, click Create New.
- Enter a name.
- Set the external IP address or range.
- Set Map to IPv4 address/range to the internal server address.
- Enable the VIP.
- For port forwarding, select the external service or port and specify the mapped internal port.
- Save the object.
A basic static VIP can be created with the CLI:
config firewall vip
edit "public-web-server"
set extip 203.0.113.50
set mappedip "10.10.20.50"
set extintf "wan1"
set status enable
next
end
Use a documentation or lab address such as 203.0.113.50 only as an example. Replace it with the public address assigned to your deployment.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Create the DNAT firewall policy
The VIP alone does not permit traffic. Create an IPv4 firewall policy from the WAN interface to the internal server or server interface.
- Go to Policy & Objects > Firewall Policy.
- Click Create New.
- Set the incoming interface to the WAN interface.
- Set the outgoing interface to the server interface.
- Use
allor a restricted source address object as appropriate. - Set the destination to the internal server address object used by the VIP.
- Set the schedule to always.
- Choose only the required service, such as HTTPS rather than ALL.
- Set the action to ACCEPT.
- Save the policy and place it in the correct order.
In Central NAT mode, this DNAT policy does not use the normal policy NAT section. The enabled VIP performs destination translation, while Central SNAT rules handle source translation where required.
Non-central NAT mode
When Central NAT is disabled, the VIP is selected in the firewall policy’s destination or NAT configuration, depending on the FortiOS interface and policy type. The policy then both permits the inbound traffic and references the VIP.
Configure IPv6 Central SNAT
IPv4 and IPv6 Central SNAT maps appear in the same Central SNAT table, but IPv6 must be enabled for the VDOM and the rule must be created as an IPv6 policy.
- In the Global VDOM, go to System > VDOM.
- Select the target VDOM and click Edit.
- Enable Central SNAT in the virtual domain settings.
- Click OK.
- Enter the target VDOM.
- Go to Policy & Objects > Central SNAT and click Create New.
- Set Type to IPv6.
- Configure the IPv6 interfaces, address objects, and IP pool.
Example:
config vdom
edit FG-traffic
config system settings
set central-nat enable
end
next
end
config vdom
edit FG-traffic
config firewall central-snat-map
edit 2
set type ipv6
set srcintf "wan2"
set dstintf "wan1"
set orig-addr6 "all"
set dst-addr6 "all"
set nat-ippool6 "test-ippool6-1"
next
end
next
end
Control source-port preservation
FortiGate enables source-port preservation by default. When the original port is available, FortiGate attempts to retain it. If preservation is disabled, it changes the source port to the next available port.
Automatic preservation applies only to source ports from 5117 through 65533. Ports below 5117 are translated to a port above 5117 unless explicit port mapping is configured.
Rank #4
- Single appliance with integrated firewalling, SD-WAN and Wi-Fi controller reduces complexity of WLAN management. Its zero-touch deployment helps optimize your onboarding experience.
- Built on a patented secure processor, this compact network firewall delivers the highest level of security and performance in its class – 800 Mbps IPS | 500 Mbps threat protection.
- User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
- Compact and fanless design equipped with 4 GE RJ45 ports (1 WAN port and 3 internal ports) provide essential connectivity and flexibility for various network configurations in a small-scale environment.
- Fortinet is the most deployed and trusted firewall from businesses worldwide with 99.98% security effectiveness, surpassing competition. Fortinet is the only vendor recognized as a firewall leader 13 consecutive years by Gartner.
For a Central SNAT rule:
config firewall central-snat-map
edit 1
set port-preserve enable
next
end
For policy NAT:
config firewall policy
edit 12
set nat enable
set port-preserve enable
next
end
ICMP has no source or destination ports. Therefore, a rule requiring explicit port mapping cannot match ICMP traffic.
Hairpin NAT
Hairpin NAT is needed when an internal client connects to an internal server by using the server’s public address or VIP. The FortiGate must translate the destination to the internal server and usually translate the source as well, so the server sends its reply back through the FortiGate.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteCreate both:
- A DNAT policy referencing the VIP.
- An SNAT policy that translates the internal client’s source address.
In non-central mode, configure the VIP under Policy & Objects > Virtual IPs. With Central NAT enabled, use Policy & Objects > DNAT & Virtual IPs and configure the source translation in Central SNAT.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Verify and troubleshoot NAT
- Confirm the NAT mode. Check System > Settings or inspect
config system settings. - Check the security policy. A policy must accept the session before Central SNAT can be applied.
- Check rule order. A broad Central SNAT rule above a specific rule will capture the traffic first.
- Check interfaces and address objects. An incorrect incoming interface, outgoing interface, source, or destination prevents a match.
- Check the VIP status. A disabled VIP is not active and cannot perform DNAT.
- Check the service and ports. Port-forwarding rules must use the correct external and mapped ports.
- Clear old sessions. NAT changes do not alter an existing session. Clear the old session and generate new traffic before testing again.
If outbound traffic works with policy NAT but stops after Central NAT is enabled, remove the assumption that the firewall policy’s NAT checkbox is still active. Create a matching entry in Policy & Objects > Central SNAT instead.
FAQ
Should NAT be enabled in the firewall policy when Central NAT is enabled?
No. With Central NAT enabled, the policy NAT option is skipped for source translation. Configure SNAT in Policy & Objects > Central SNAT or in config firewall central-snat-map.
Does Central SNAT run before the firewall policy?
No. Fortinet documents Central SNAT as being applied after the security policy. A denied session is not rescued by a matching SNAT rule.
Why is my Central SNAT rule not matching?
Check the rule order, interfaces, source and destination objects, protocol, ports, enabled status, and the security policy. Central SNAT evaluates rules top down and uses the first match.
Best Value
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Do I need to enable NAT in a policy for port forwarding?
In Central NAT mode, no. Create and enable a VIP, then create a firewall policy that allows traffic to the VIP’s translated internal destination. Source NAT, if needed, is configured separately in Central SNAT.
Why does my VIP not forward traffic?
Confirm that the VIP is enabled, its external address and mapped address are correct, the external interface is correct, and an inbound firewall policy allows the required service to the translated server.
Can source-port preservation preserve every original port?
No. Automatic preservation applies to ports 5117 through 65533. Lower ports require explicit port mapping. Explicit port mapping also requires an Overload IP pool and cannot be used for ICMP.
Why did traffic continue using the old NAT address after I changed the configuration?
Existing sessions retain their original translation. Clear the existing session and create a new connection before verifying the change.
How do I configure IPv6 Central SNAT?
Enable Central SNAT for the target VDOM, open Policy & Objects > Central SNAT, create a rule, and set Type to IPv6. IPv4 and IPv6 maps appear in the same table.
The Bottom Line
For ordinary outbound translation, use policy NAT when Central NAT is disabled: edit the IPv4 firewall policy and enable NAT. For Central NAT deployments, leave the policy NAT option out of the design and create an ordered rule under Policy & Objects > Central SNAT. For inbound publishing and port forwarding, create an enabled VIP and an allowing firewall policy. Finally, clear old sessions whenever you change NAT so the test uses the new translation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

