{"id":412,"date":"2026-08-10T12:38:15","date_gmt":"2026-08-10T07:08:15","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/fortigate-source-nat-configuration-for-internet-access\/"},"modified":"2026-09-19T15:38:50","modified_gmt":"2026-09-19T10:08:50","slug":"fortigate-source-nat-configuration-for-internet-access","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/","title":{"rendered":"FortiGate Source NAT Configuration for Internet Access"},"content":{"rendered":"<p>Internal network endpoints use private IPv4 addresses defined by RFC 1918. Public internet routers drop private IP addresses. Therefore, outbound client traffic must undergo Source Network Address Translation (SNAT) before exiting your boundary firewall. Performing a <strong>FortiGate source NAT configuration<\/strong> ensures that internal clients can access web resources while masking their private network structure behind routed public addresses.<\/p>\n<p>This technical tutorial walks you through configuring policy-based Source NAT on a FortiGate firewall running FortiOS. You will learn how to configure NAT using both the outgoing interface address and dedicated dynamic IP pools, inspect the session table, and troubleshoot translation issues using CLI diagnostic tools.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>An enterprise organization requires internet access for two distinct internal networks connected to a FortiGate firewall:<\/p>\n<ul>\n<li><strong>General LAN Workstations (10.0.10.0\/24):<\/strong> Standard user devices requiring web browsing access. Their outbound connections should translate directly to the IP address assigned to the WAN interface.<\/li>\n<li><strong>Application Servers (10.0.20.0\/24):<\/strong> Internal servers requiring outbound internet access for updates and API connectivity. To avoid reputation issues and keep client browsing traffic isolated, these servers must translate to a dedicated block of public IP addresses (IP Pool).<\/li>\n<\/ul>\n<p>The FortiGate connects to the Internet Service Provider (ISP) on interface <code>port1<\/code> using a static public address range in <code>198.51.100.0\/24<\/code>.<\/p>\n<h2>Lab Topology<\/h2>\n<p>The network topology below illustrates the traffic path from internal subnets through the FortiGate firewall to the ISP gateway.<\/p>\n<pre>\n[ General Workstations ] \n    (10.0.10.0\/24)\n          |\n          +------&gt; [ port2: 10.0.10.1 ]\n                                      |\n[ App Servers ]                       |----&gt; [ FortiGate Firewall ] ----&gt; [ port1: 198.51.100.2\/24 ] ----&gt; [ ISP Router: 198.51.100.1 ] ----&gt; Internet\n    (10.0.20.0\/24)                    |\n          +------&gt; [ port3: 10.0.20.1 ]\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The following table lists the lab values and firewall objects used throughout this tutorial. Adapt these values to match your production environment.<\/p>\n<table>\n<thead>\n<tr>\n<th>Object \/ Interface Name<\/th>\n<th>Type \/ Class<\/th>\n<th>Value \/ Address Range<\/th>\n<th>Purpose<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>port1<\/code><\/td>\n<td>Physical Interface<\/td>\n<td><code>198.51.100.2\/24<\/code><\/td>\n<td>WAN interface connected to the ISP gateway (<code>198.51.100.1<\/code>).<\/td>\n<\/tr>\n<tr>\n<td><code>port2<\/code><\/td>\n<td>Physical Interface<\/td>\n<td><code>10.0.10.1\/24<\/code><\/td>\n<td>LAN gateway interface for general workstations.<\/td>\n<\/tr>\n<tr>\n<td><code>port3<\/code><\/td>\n<td>Physical Interface<\/td>\n<td><code>10.0.20.1\/24<\/code><\/td>\n<td>DMZ gateway interface for application servers.<\/td>\n<\/tr>\n<tr>\n<td><code>net-LAN-10.0.10.0_24<\/code><\/td>\n<td>Firewall Address Object<\/td>\n<td><code>10.0.10.0\/255.255.255.0<\/code><\/td>\n<td>Defines the LAN workstation subnet.<\/td>\n<\/tr>\n<tr>\n<td><code>net-Servers-10.0.20.0_24<\/code><\/td>\n<td>Firewall Address Object<\/td>\n<td><code>10.0.20.0\/255.255.255.0<\/code><\/td>\n<td>Defines the server subnet.<\/td>\n<\/tr>\n<tr>\n<td><code>ippool-WAN-Outbound<\/code><\/td>\n<td>IP Pool Object<\/td>\n<td><code>198.51.100.10 - 198.51.100.12<\/code><\/td>\n<td>Dynamic IP pool (Overload) for outgoing server SNAT.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Verify that your firewall meets these baseline requirements before configuring Source NAT:<\/p>\n<ul>\n<li>The WAN interface is configured with an active IPv4 address and link state is up.<\/li>\n<li>A default static route exists pointing outbound traffic to the ISP next-hop gateway (for example, <code>0.0.0.0\/0<\/code> via <code>198.51.100.1<\/code> on <code>port1<\/code>).<\/li>\n<li>Internal client devices are configured with default gateways pointing to their respective FortiGate interface IPs.<\/li>\n<li>Administrative access to the GUI or CLI is available.<\/li>\n<\/ul>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<p>In FortiOS, policy NAT allows you to enable translation directly inside the firewall policy. This section details how to build address objects, IP pools, and firewall policies in the FortiGate GUI.<\/p>\n<p>For related configuration, see the <a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-a-static-default-route-on-fortigate\/\">FortiGate static default route guide<\/a> and <a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-firewall-policy-configuration-with-a-real-life-example\/\">FortiGate firewall policy guide<\/a>.<\/p>\n<h3>Step 1: Create Firewall Address Objects<\/h3>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Addresses<\/strong>.<\/li>\n<li>Click <strong>Create New &gt; Address<\/strong>.<\/li>\n<li>Configure the LAN address object:\n<ul>\n<li><strong>Name:<\/strong> <code>net-LAN-10.0.10.0_24<\/code><\/li>\n<li><strong>Type:<\/strong> Subnet<\/li>\n<li><strong>IP\/Netmask:<\/strong> <code>10.0.10.0\/24<\/code><\/li>\n<li><strong>Interface:<\/strong> Any (or select <code>port2<\/code>)<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<li>Repeat the process for the server subnet:\n<ul>\n<li><strong>Name:<\/strong> <code>net-Servers-10.0.20.0_24<\/code><\/li>\n<li><strong>Type:<\/strong> Subnet<\/li>\n<li><strong>IP\/Netmask:<\/strong> <code>10.0.20.0\/24<\/code><\/li>\n<li><strong>Interface:<\/strong> Any (or select <code>port3<\/code>)<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 2: Create an Outbound IP Pool<\/h3>\n<p>When you need traffic to translate to a designated public IP rather than the primary interface address, create an IP Pool object.<\/p>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; IP Pools<\/strong>.<\/li>\n<li>Click <strong>Create New &gt; IP Pool<\/strong>.<\/li>\n<li>Configure the pool parameters:\n<ul>\n<li><strong>Name:<\/strong> <code>ippool-WAN-Outbound<\/code><\/li>\n<li><strong>Type:<\/strong> Overload (Port Address Translation \/ PAT)<\/li>\n<li><strong>External IP Range:<\/strong> <code>198.51.100.10 - 198.51.100.12<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<p><em>Note: The <strong>Overload<\/strong> type uses Port Address Translation, allowing thousands of internal connections to share a small range of public IPs. The <strong>One-to-One<\/strong> type maps single internal IPs to single public IPs without port translation.<\/em><\/p>\n<h3>Step 3: Configure Firewall Policy Using Outgoing Interface Address<\/h3>\n<p>This policy allows workstation traffic to reach the internet, translating the source IP to the <code>port1<\/code> IP address (<code>198.51.100.2<\/code>).<\/p>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Firewall Policy<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Enter the policy details:\n<ul>\n<li><strong>Name:<\/strong> <code>LAN-to-WAN-SNAT<\/code><\/li>\n<li><strong>Incoming Interface:<\/strong> <code>port2<\/code><\/li>\n<li><strong>Outgoing Interface:<\/strong> <code>port1<\/code><\/li>\n<li><strong>Source:<\/strong> <code>net-LAN-10.0.10.0_24<\/code><\/li>\n<li><strong>Destination:<\/strong> <code>all<\/code><\/li>\n<li><strong>Schedule:<\/strong> <code>always<\/code><\/li>\n<li><strong>Service:<\/strong> <code>ALL<\/code><\/li>\n<li><strong>Action:<\/strong> <code>ACCEPT<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Scroll to the <strong>Firewall \/ Network Options<\/strong> section.<\/li>\n<li>Toggle <strong>NAT<\/strong> to the enabled position.<\/li>\n<li>Select <strong>Use Outgoing Interface Address<\/strong>.<\/li>\n<li>Click <strong>OK<\/strong> to save the policy.<\/li>\n<\/ol>\n<h3>Step 4: Configure Firewall Policy Using an IP Pool<\/h3>\n<p>This policy allows server traffic to reach the internet using the pool of public IP addresses created in Step 2.<\/p>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Firewall Policy<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Enter the policy details:\n<ul>\n<li><strong>Name:<\/strong> <code>Servers-to-WAN-PoolNAT<\/code><\/li>\n<li><strong>Incoming Interface:<\/strong> <code>port3<\/code><\/li>\n<li><strong>Outgoing Interface:<\/strong> <code>port1<\/code><\/li>\n<li><strong>Source:<\/strong> <code>net-Servers-10.0.20.0_24<\/code><\/li>\n<li><strong>Destination:<\/strong> <code>all<\/code><\/li>\n<li><strong>Schedule:<\/strong> <code>always<\/code><\/li>\n<li><strong>Service:<\/strong> <code>ALL<\/code><\/li>\n<li><strong>Action:<\/strong> <code>ACCEPT<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Toggle <strong>NAT<\/strong> to the enabled position.<\/li>\n<li>Select <strong>Use Dynamic IP Pool<\/strong>.<\/li>\n<li>Add <code>ippool-WAN-Outbound<\/code> under <strong>Custom IP Pool<\/strong>.<\/li>\n<li>Click <strong>OK<\/strong> to save the policy.<\/li>\n<\/ol>\n<h2>Step-by-Step CLI Configuration<\/h2>\n<p>Network engineers who prefer command-line deployment can configure the exact same components using the FortiOS CLI.<\/p>\n<h3>1. Create Address Objects<\/h3>\n<pre><code>config firewall address\n    edit \"net-LAN-10.0.10.0_24\"\n        set subnet 10.0.10.0 255.255.255.0\n    next\n    edit \"net-Servers-10.0.20.0_24\"\n        set subnet 10.0.20.0 255.255.255.0\n    next\nend\n<\/code><\/pre>\n<h3>2. Create the IP Pool Object<\/h3>\n<pre><code>config firewall ippool\n    edit \"ippool-WAN-Outbound\"\n        set type overload\n        set startip 198.51.100.10\n        set endip 198.51.100.12\n    next\nend\n<\/code><\/pre>\n<h3>3. Create Policy 1 (Outgoing Interface NAT)<\/h3>\n<pre><code>config firewall policy\n    edit 1\n        set name \"LAN-to-WAN-SNAT\"\n        set srcintf \"port2\"\n        set dstintf \"port1\"\n        set action accept\n        set srcaddr \"net-LAN-10.0.10.0_24\"\n        set dstaddr \"all\"\n        set schedule \"always\"\n        set service \"ALL\"\n        set nat enable\n    next\nend\n<\/code><\/pre>\n<h3>4. Create Policy 2 (Dynamic IP Pool NAT)<\/h3>\n<pre><code>config firewall policy\n    edit 2\n        set name \"Servers-to-WAN-PoolNAT\"\n        set srcintf \"port3\"\n        set dstintf \"port1\"\n        set action accept\n        set srcaddr \"net-Servers-10.0.20.0_24\"\n        set dstaddr \"all\"\n        set schedule \"always\"\n        set service \"ALL\"\n        set nat enable\n        set ippool enable\n        set poolname \"ippool-WAN-Outbound\"\n    next\nend\n<\/code><\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding the order of packet processing in FortiOS helps prevent misconfigurations. FortiGate processes outbound traffic using a strict state-machine flow:<\/p>\n<ol>\n<li><strong>Ingress Lookup &amp; FIB Check:<\/strong> The packet arrives on the ingress interface (e.g., <code>port2<\/code>). The FortiGate inspects the destination IP address and queries the Routing Information Base (RIB\/FIB) to determine the egress interface. <em>Routing always happens before firewall policy matching.<\/em><\/li>\n<li><strong>Firewall Policy Matching:<\/strong> FortiGate evaluates the active policy list top-down. It looks for a match on incoming interface, outgoing interface, source address, destination address, service, and schedule.<\/li>\n<li><strong>Source NAT Evaluation:<\/strong> Once policy match occurs, FortiGate evaluates the policy NAT settings:\n<ul>\n<li>If NAT is set to <strong>Use Outgoing Interface Address<\/strong>, FortiGate replaces the packet&#8217;s source IP address with the IP assigned to egress interface <code>port1<\/code>. It allocates a dynamic source port from its ephemeral range.<\/li>\n<li>If NAT is set to an <strong>IP Pool<\/strong>, FortiGate selects an available IP from the assigned pool range and overwrites the source IP and port accordingly.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Session Table Entry Creation:<\/strong> FortiGate records the translation details in its stateful kernel session table.<\/li>\n<li><strong>Egress Processing:<\/strong> The packet exits <code>port1<\/code> into the ISP network with rewritten source headers.<\/li>\n<li><strong>Inbound Return Traffic:<\/strong> When the external server responds, the destination address matches the session table entry created in step 4. FortiGate un-NATs the packet (rewriting the public destination back to the original client IP) and routes it back to the internal host.<\/li>\n<\/ol>\n<p><em>Note on Central NAT: By default, FortiGate uses policy-based NAT where translation rules sit inside the firewall policy. If your organization enables Central NAT (`config system settings -&gt; set central-nat enable`), translation rules are managed separately under `config firewall central-snat-map`.<\/em><\/p>\n<h2>Verification<\/h2>\n<p>After completing your <strong>FortiGate source NAT configuration<\/strong>, verify operational state from both the client and the firewall CLI.<\/p>\n<h3>1. Client-Side Test<\/h3>\n<p>From an internal workstation (<code>10.0.10.50<\/code>), initiate an outbound web request or ICMP ping:<\/p>\n<pre><code>curl https:\/\/ifconfig.me\n<\/code><\/pre>\n<p>The response must display the firewall WAN interface IP address (<code>198.51.100.2<\/code>). If performed from a host in the server subnet (<code>10.0.20.50<\/code>), the response will display one of the pool addresses (e.g., <code>198.51.100.10<\/code>).<\/p>\n<h3>2. Session Table Check via CLI<\/h3>\n<p>Filter and view the active firewall sessions on the FortiGate CLI to confirm stateful tracking and translation entries.<\/p>\n<pre><code>diagnose sys session filter src 10.0.10.50\ndiagnose sys session list\n<\/code><\/pre>\n<p>Expected output snippet:<\/p>\n<pre>\nsession info: proto=6 proto_state=01 duration=12 expire=3588 timeout=3600 flags=00000000 dev=3\/4 gwy=198.51.100.1\/4\n...\norgin to sub: org: 10.0.10.50:49210 reply: 198.51.100.1:443 dev=3-&gt;4\nreply to sub: org: 198.51.100.1:443 reply: 198.51.100.2:49210 dev=4-&gt;3\n...\nhook=post act=snat algo=nat\n<\/pre>\n<p>This session entry proves that outbound traffic from source <code>10.0.10.50<\/code> is translated to <code>198.51.100.2<\/code> on egress.<\/p>\n<h2>Troubleshooting<\/h2>\n<p>If traffic fails to translate or outbound access fails, use the following structured troubleshooting workflow.<\/p>\n<h3>Troubleshooting Workflow<\/h3>\n<pre>\nLink\/Interface Status ---&gt; Routing Table Check ---&gt; Policy Match Check ---&gt; Session Creation ---&gt; Flow Trace Debug\n<\/pre>\n<h3>Step 1: Check Routing<\/h3>\n<p>Verify that FortiGate has a valid route to the destination network. Without a valid egress route, policy matching never occurs.<\/p>\n<pre><code>get router info routing-table all\nget router info routing-table details 0.0.0.0\n<\/code><\/pre>\n<h3>Step 2: Trace Packet Execution with Debug Flow<\/h3>\n<p>The packet trace tool identifies if traffic is dropped due to routing failures, implicit deny policies, or misconfigured NAT pools.<\/p>\n<p><strong>CAUTION:<\/strong> Running debug commands on high-throughput production firewalls can generate large volumes of console log output. Always restrict debug traces using restrictive filters.<\/p>\n<p>Execute the trace syntax:<\/p>\n<pre><code>diagnose debug reset\ndiagnose debug flow filter saddr 10.0.10.50\ndiagnose debug flow filter daddr 1.1.1.1\ndiagnose debug flow show console enable\ndiagnose debug flow trace start 10\ndiagnose debug enable\n<\/code><\/pre>\n<p>Look for lines indicating successful policy matching and NAT handling in the output trace:<\/p>\n<pre>\nid=65250 trace_id=1 msg=\"allocate a new session-0001abcd\"\nid=65250 trace_id=1 msg=\"find a route: flag=00000001 gw-198.51.100.1 via port1\"\nid=65250 trace_id=1 msg=\"Allowed by Policy-1: SNAT\"\nid=65250 trace_id=1 msg=\"snat change connection source 10.0.10.50:52100 to 198.51.100.2:52100\"\n<\/pre>\n<p>Disable debug logging immediately after testing:<\/p>\n<pre><code>diagnose debug disable\ndiagnose debug reset\n<\/code><\/pre>\n<h3>Troubleshooting Matrix<\/h3>\n<table>\n<thead>\n<tr>\n<th>Symptom<\/th>\n<th>Likely Root Cause<\/th>\n<th>Verification Command \/ Action<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Client ping times out, trace shows <code>\"Reverse path check fail\"<\/code><\/td>\n<td>Asymmetric routing or missing return route on external device.<\/td>\n<td>Verify ISP default gateway configuration and upstream router routes.<\/td>\n<\/tr>\n<tr>\n<td>Trace displays <code>\"Implicit Deny\"<\/code><\/td>\n<td>Policy mismatch or disabled NAT parameter.<\/td>\n<td>Ensure source\/destination address objects match client traffic profiles.<\/td>\n<\/tr>\n<tr>\n<td>Server receives connection from WAN interface IP instead of pool IP<\/td>\n<td>Firewall policy misconfiguration or incorrect policy order.<\/td>\n<td>Move the IP Pool policy above the general internet access policy in the list.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Common Mistakes<\/h2>\n<ul>\n<li><strong>Incorrect Policy Ordering:<\/strong> FortiGate reads firewall policies top-down. If a broad rule matching source <code>all<\/code> with interface NAT sits above your specific IP pool policy, traffic matches the broader rule first. Always place specific pool policies higher in the list.<\/li>\n<li><strong>Forgetting IP Pool Type (Overload vs One-to-One):<\/strong> Setting an IP pool type to &#8220;One-to-One&#8221; when you have fewer public IPs than internal hosts causes translation failure once all public IPs are assigned. Use &#8220;Overload&#8221; for multi-client translation.<\/li>\n<li><strong>Missing Upstream ARP Response for Pool IPs:<\/strong> When using an IP Pool that is on the same subnet as the WAN interface, the ISP gateway sends ARP requests for the pool IPs. Ensure the FortiGate responds to ARP requests for pool IPs (enabled by default when using Overload pools).<\/li>\n<li><strong>Assuming NAT Routing:<\/strong> NAT does not replace routing. FortiGate must know the outbound interface via a routing lookup *before* it can apply policy NAT rules.<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>Keep these critical best practices in mind when deploying Source NAT in high-availability or enterprise environments:<\/p>\n<ul>\n<li><strong>Port Exhaustion Prevention:<\/strong> A single public IP address using Overload PAT can support roughly 60,000 simultaneous TCP\/UDP source port allocations. For networks with thousands of active internal endpoints, expand the IP Pool range to include multiple IP addresses to prevent port exhaustion.<\/li>\n<li><strong>High Availability (HA) Clusters:<\/strong> Session tables and IP pool states synchronize across active\/passive FortiGate clusters automatically. When a failover occurs, connections translated via interface address or IP pool resume instantly without manually shifting IP pool properties.<\/li>\n<li><strong>Logging NAT Allocations:<\/strong> In regulated networks, compliance guidelines require mapping outbound connections back to internal client source IPs. Enable session logging on all outbound policies by setting <code>set logtraffic all<\/code> in the CLI policy configuration.<\/li>\n<li><strong>Fixed Port Block Allocation:<\/strong> For strict compliance frameworks where port range tracking is required per user subnet, use the <code>fixed-port-range<\/code> IP pool type rather than standard <code>overload<\/code>.<\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Configuring Source NAT on a FortiGate firewall is an essential requirement for secure, outbound internet access. By configuring policy-based NAT using the outgoing interface IP or dynamic IP pools, administrators can safely route internal user traffic across public networks. Always sequence your policy table correctly, ensure routing entries precede NAT rules, and use session diagnostics to verify state translations in your network.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn FortiGate source NAT configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":411,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[4],"tags":[28,29,41,67,44,43,65],"class_list":["post-412","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fortinet","tag-beginner","tag-firewall-tutorial","tag-fortigate","tag-fortigate-source-nat-configuration","tag-fortinet","tag-fortios","tag-nat"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>FortiGate Source NAT Configuration for Internet Access<\/title>\n<meta name=\"description\" content=\"Learn FortiGate source NAT configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FortiGate Source NAT Configuration for Internet Access\" \/>\n<meta property=\"og:description\" content=\"Learn FortiGate source NAT configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-10T07:08:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-19T10:08:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/fortigate-source-nat-configuration-for-internet-access-featured.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"FortiGate Source NAT Configuration for Internet Access\",\"datePublished\":\"2026-08-10T07:08:15+00:00\",\"dateModified\":\"2026-09-19T10:08:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/\"},\"wordCount\":1707,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/fortigate-source-nat-configuration-for-internet-access-featured.png\",\"keywords\":[\"Beginner\",\"Firewall Tutorial\",\"FortiGate\",\"FortiGate source NAT configuration\",\"Fortinet\",\"FortiOS\",\"NAT\"],\"articleSection\":[\"FortiGate\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/\",\"name\":\"FortiGate Source NAT Configuration for Internet Access\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/fortigate-source-nat-configuration-for-internet-access-featured.png\",\"datePublished\":\"2026-08-10T07:08:15+00:00\",\"dateModified\":\"2026-09-19T10:08:50+00:00\",\"description\":\"Learn FortiGate source NAT configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/fortigate-source-nat-configuration-for-internet-access-featured.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/fortigate-source-nat-configuration-for-internet-access-featured.png\",\"width\":1200,\"height\":630,\"caption\":\"FortiGate Source NAT Configuration for Internet Access\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-source-nat-configuration-for-internet-access\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FortiGate Source NAT Configuration for Internet Access\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"FortiGate Source NAT Configuration for Internet Access","description":"Learn FortiGate source NAT configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/","og_locale":"en_US","og_type":"article","og_title":"FortiGate Source NAT Configuration for Internet Access","og_description":"Learn FortiGate source NAT configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/","og_site_name":"NetworkFix","article_published_time":"2026-08-10T07:08:15+00:00","article_modified_time":"2026-09-19T10:08:50+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/fortigate-source-nat-configuration-for-internet-access-featured.png","type":"image\/png"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"FortiGate Source NAT Configuration for Internet Access","datePublished":"2026-08-10T07:08:15+00:00","dateModified":"2026-09-19T10:08:50+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/"},"wordCount":1707,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/fortigate-source-nat-configuration-for-internet-access-featured.png","keywords":["Beginner","Firewall Tutorial","FortiGate","FortiGate source NAT configuration","Fortinet","FortiOS","NAT"],"articleSection":["FortiGate"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/","url":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/","name":"FortiGate Source NAT Configuration for Internet Access","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/fortigate-source-nat-configuration-for-internet-access-featured.png","datePublished":"2026-08-10T07:08:15+00:00","dateModified":"2026-09-19T10:08:50+00:00","description":"Learn FortiGate source NAT configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/fortigate-source-nat-configuration-for-internet-access-featured.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/fortigate-source-nat-configuration-for-internet-access-featured.png","width":1200,"height":630,"caption":"FortiGate Source NAT Configuration for Internet Access"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"FortiGate Source NAT Configuration for Internet Access"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=412"}],"version-history":[{"count":3,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/412\/revisions"}],"predecessor-version":[{"id":1609,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/412\/revisions\/1609"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/411"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}