Chapter 3. NAT
3.1 Source NAT
Learning Objectives
- Configure a NAT policy in FortiGate
- Identify source NAT
Scenario: We are going to enable Source NAT (SNAT) to reach the Internet from Kali. That means that all traffic from the local network to the Internet should be allowed.
Source NAT
| Device | IP address | Access |
|---|---|---|
| Kali | DHCP Client | – |
| WordPress/Kali | DHCP Client | – |
| Ethernet Switch | – | – |
| FortiGate | Port 2 – (<IP_ADDRESS>/24) – DHCP Server (<IP_ADDRESS> to <IP_ADDRESS>)
Port 3 – DHCP Client Port 4 – <IP_ADDRESS>/24 |
ICMP-HTTP-HTTPS |
| WebTerm | <IP_ADDRESS>/24 | – |
Basic Configuration
- Port configuration in the firewall as follows:
- Set a DHCP server on interface port2 (Range of IP address should be: <IP_ADDRESS> to <IP_ADDRESS>, DNS: <IP_ADDRESS>).
- Set port3 as a DHCP client and connect to the NAT.
- Set a static route in the firewall to reach to NAT object.
- Go to Policy & Objects > Firewall Policy section, click Create New to add a new firewall policy, and configure the following settings:
- Name: LocalToInternet
- From inside to outside (port2 to port3)
- Source: Create an address for the local network (Subnet: <IP_ADDRESS>/24)
- Destination: all
- Schedule: Always
- Service: Only HTTP, HTTPS, and DNS
- Action: Accept
- Open the browser in Kali, you should be able to access the internet.