Configure Hairpin NAT (VIP) in Fortigate Firewall (Client and server behind same firewall interface)

preview_player
Показать описание
How to configure Hairpin NAT in Fortigate Firewall
Debug logs for the hairpin NAT
session information for the hairpin NAT
Please donate to support the channel:
================================
Рекомендации по теме
Комментарии
Автор

what you are saying at around 13:00 isnt true. A fortigate is stateful, meaning you don't have to a: create a reversed policy for your scenario and b not enable NAT. The VIP already does address translation and the fortigate knows without adding NAT in the policy the way back during the active session.

radeondutch
Автор

The second policy you have configured in which NAT is disabled for lan to wan. Then how users will access the Internet?

rajneeshrai
Автор

Hi, can we also use src and destination interface to be same for internal hairpin nat ?? Also, in fortigate documents I have read command "set match vip enable". What difference does this comman make ??

niravchauhan
Автор

Can this work with SD-WAN setup? I am planning to configure SDWAN and VIP.

amak