FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
lingky88
Staff
Staff
Article Id 308101
Description This article describes how the user can use FortiManager to install Virtual Server changes to their managed FortiGates operating in Central NAT mode using FortiManager.
Scope FortiManager.
Solution
  1. On the FortiGate, the central NAT setting is enabled.

 

1. FGT enable central NAT.png

 

  1. On the FortiManager, the policy package has Central NAT enabled.

 

2. FMG policy central NAT mode.png

 

 

  1. Create the Virtual Server on FortiManager -> Policy & Objects -> Object Configurations -> Firewall Objects -> Virtual Servers.

 

3. FMG Virtual Server.png

 

  1. When FortiGate operates in central NAT mode, it is not required to apply a VIP/Virtual Server onto a firewall policy. Hence, when trying to install, the Install Preview does not show the Virtual Server/VIP configuration being installed.

 

4. Install Preview blank.png

 

  1. It is mandatory to import the Virtual Server/VIP configured under Policy & Objects -> Select the Policy Package -> Central DNAT setting of the Policy Package in FortiManager for the change to be installed.

 

5. Import VS1.png

 

6. Import VS2.png

 

  1. Install the policy package again and we are now able to see the Virtual Server configuration that we had created in the Install Preview.

 

7. Install Preview.png

Contributors