Fortigate Static NAT Configuration

Fortigate Static NAT Configuration

We will give an example on how to configure static NAT in Fortigate. In this example, we use the WAN 1 Interface of the FortiGate unit is connected to the Internet and the Internal interface is connected to the DMZ network. We need to access one of the DMZ servers which is from the Internet for any services. (Please note that this example is using  v4.0,build0535,120511 (MR3 Patch 7) ).

Let say the Internet IP address blocks that we get from the Internet Service Provider are and we want to NAT the IP Address into our web server IP Address 


Example Topology

Before we can access the NAT IP Address, we have to create a Virtual IP using the following steps:

  1. Go to Firewall Objects > Virtual IP > Virtual IP.
  2. Select Create New.
  3. Complete the following and select OK.
    • Name : Web_Server_NAT (can be filled with any names)
    • External Interface  : wan1
    • Type  : Static NAT
    • External IP Address/Range:
    • Mapped IP Address/Range:
    • No Port Forwarding Selected

After finishing create the Virtual IP then Create the Policy using the following steps:

  1. Go to Policy> Policy > Policy  and select  Create New
  2. Complete the following and select OK.
  3. Here is the form:
    • Source Interface/Zone: wan1
    • Source Address: All
    • Destination Interface/Zone: Internal
    • Destination Address: Web_Server_NAT (select from the one we have created on above steps)
    • Schedule : always
    • Service : ANY
    • Action: ACCEPT
    • Select the NAT option
    • Select OK

After completing all the steps above then test using ping to from Internet and it should be success.

Article Fortigate Static NAT Configuration is written by JK.


3.4 5 votes
Article Rating

We are teams that have the same hobbies in Information Technologies and have experienced in many fields regarding Information Technologies .

Related Articles

Notify of
Inline Feedbacks
View all comments
kapil vats

Dear Team,
I Was done configuration as per above but public IP is not pinging from internet but showing public IP when i was checking on same system through what is my IP. Please suggest to resolve issue ASAP.

Would love your thoughts, please comment.x