A real-life situation
FGT1's LAN users leave the Internet as 203.0.113.2, the port1 address. A payment provider now asks for FGT1's public address to whitelist, but the company wants payment traffic to use its own address, separate from everyday browsing. The ISP has routed a small extra block, 203.0.113.16/29, to FGT1. An IP pool puts those addresses to work.
NAT with the interface address
With set nat enable and no pool, the FortiGate uses the outgoing interface's address and changes the source port when needed to keep sessions apart, the same as PAT on a home router:
- Source IP
- 10.0.1.10
- Source port
- 51544
- Destination IP
- 198.51.100.80
- Destination port
- 443
- Source IP
- 203.0.113.2 (rewritten)
- Source port
- 51544 (or another free port) (rewritten)
- Destination IP
- 198.51.100.80
- Destination port
- 443
Highlighted fields were rewritten by the router.
IP pool types
| Type | How it maps | Use it when |
|---|---|---|
| Overload (default) | Many inside hosts → the pool's addresses, with port translation | General Internet access from a chosen address or addresses |
| One-to-one | Each inside host → its own pool address, no port change; new hosts fail when the pool is used up | Protocols or partners that need one address per host |
| Fixed port range | An inside range → the pool, with a fixed, calculable port range per inside address | Large networks where you must trace a public address and port back to a user without logs |
| Port block allocation | Each inside host gets blocks of ports on a pool address, on demand | Carrier-grade NAT: fewer log entries (one per block, not per session) |
Configure an overload pool and use it
config firewall ippool
edit Payments-Pool
set type overload
set startip 203.0.113.17
set endip 203.0.113.17
next
end
config firewall policy
edit 5
set name "LAN-to-Payments"
set srcintf "port2"
set dstintf "port1"
set srcaddr "LAN-subnet"
set dstaddr "Payment-Provider"
set action accept
set schedule "always"
set service "HTTPS"
set nat enable
set ippool enable
set poolname "Payments-Pool"
set logtraffic all
next
move 5 before 3
endThe policy must sit above the general LAN-to-Internet policy (3), or that one matches first. Payment-Provider is an address object for the provider's servers.
Verify the translation
FGT1 # diagnose sys session list session info: proto=6 proto_state=01 ... hook=post dir=org act=snat 10.0.1.10:51870->192.0.2.50:443(203.0.113.17:51870) hook=pre dir=reply act=dnat 192.0.2.50:443->203.0.113.17:51870(10.0.1.10:51870) misc=0 policy_id=5 ...
diagnose firewall ippool-all listLists the configured pools and their ranges.
Why it works this way
Translation is part of the decision to allow traffic, so in policy NAT mode it lives on the policy: different policies can translate the same users differently depending on where they go. The pool type is a trade-off between saving public addresses (overload), keeping addresses stable per host (one-to-one), and making translations traceable with little logging (fixed port range, port block allocation).
Common mistakes
- Creating the pool and enabling NAT, but forgetting
set ippool enable: traffic uses the interface address. - Putting the more specific NAT policy below the general one, so it never matches.
- Using pool addresses the ISP doesn't route to the FortiGate: replies go nowhere.
- Choosing one-to-one for general browsing and running out of addresses.
Key takeaways
- In policy NAT mode, source NAT is enabled per policy.
- Without a pool, the outgoing interface address is used, with port translation.
- Pools: overload (shared), one-to-one, fixed port range, port block allocation.
- The session list shows the translated address in brackets after act=snat.
Check yourself
A policy has nat enable and no IP pool. Which address do LAN users appear as on the Internet?
200 users must share 2 public addresses. Which pool type?
In the session list, what does act=snat 10.0.1.10:51870->192.0.2.50:443(203.0.113.17:51870) show?