Planning the configuration | Quick Configuration Guide |
NAT/Route mode
In NAT/Route mode, the FortiGate-5001FA2 security system is visible to the networks that it is connected to. Each interface connected to a network must be configured with an IP address that is valid for that network. In many configurations, in NAT/Route mode all of the FortiGate interfaces are on different networks, and each network is on a separate subnet.
You would typically use NAT/Route mode when the FortiGate-5001FA2 security system is deployed as a gateway between private and public networks. In the default NAT/Route mode configuration, the FortiGate-5001FA2 security system functions as a firewall. Firewall policies control communications through the FortiGate-5001FA2 security system. No traffic can pass through the FortiGate-5001FA2 security system until you add firewall policies.
In NAT/Route mode, firewall policies can operate in NAT mode or in Route mode. In NAT mode, the FortiGate firewall performs network address translation before IP packets are sent to the destination network. In Route mode, no translation takes place.
Figure 7: Example FortiGate-5001FA2 board operating in NAT/Route mode
| Internet | |
NAT mode policies | | | NAT mode policies |
controlling traffic between | port2 | | controlling traffic between |
internal and external | FortiGate-5001FA2 module | internal and external |
networks. | 204.23.1.2 | in NAT/Route mode | networks. |
| USB | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 |
| CONSOLE | | | | | | | | |
| PWR ACC | | | | | | | | STA IPM |
Internal | port1 | | | | port3 | | | | Internal |
192.168.1.99 | | | | 10.10.10.1 | |
network | | | | | | | | | network |
Route mode policies controlling traffic between Internal networks.
Transparent mode
In Transparent mode, the FortiGate-5001FA2 security system is invisible to the network. All of the FortiGate-5001FA2 interfaces are connected to different segments of the same network. In Transparent mode you only have to configure a management IP address so that you can connect to the FortiGate-5001FA2 security system to make configuration changes and so the FortiGate-5001FA2 security system can connect to external services such as the FortiGuard Distribution Network (FDN).
| FortiGate-5001FA2 Security System Guide |
22 | 01-30000-0379-20080606 |