Fortinet black logo

Administration Guide

NAT66, NAT46, NAT64, and DNS 64

NAT66, NAT46, NAT64, and DNS 64

Multiple NAT46 and NAT64 related objects are consolidated into regular objects. A per-VDOM virtual interface, naf.<vdom>, is automatically added to process NAT46 and NAT64 traffic. The features include:

  • vip46 and vip64 settings are consolidated in vip and vip6 configurations.

  • policy46 and policy64 settings are consolidated in firewall policy settings.

  • nat46 and nat64 are included in firewall policy settings.

  • ippool and ippool6 support NAT46 and NAT64 (when enabled, the IP pool should match a subnet).

  • Central SNAT supports NAT46 and NAT64.

  • add-nat46-route in ippool6 and add-nat64-route in ippool are enabled by default. The FortiGate generates a static route that matches the IP range in ippool6 or ippool for the naf tunnel interface.

Note

Automatic processing of the naf tunnel interface is not supported in security policies.

To configure NAT46 or NAT64 translation, use the standard vip or vip6 setting, apply it in a firewall policy, enable NAT46 or NAT64, and enter the IP pool to complete the configuration.

Note

The external IP address cannot be the same as the external interface IP address.

This section includes:

NAT66, NAT46, NAT64, and DNS 64

Multiple NAT46 and NAT64 related objects are consolidated into regular objects. A per-VDOM virtual interface, naf.<vdom>, is automatically added to process NAT46 and NAT64 traffic. The features include:

  • vip46 and vip64 settings are consolidated in vip and vip6 configurations.

  • policy46 and policy64 settings are consolidated in firewall policy settings.

  • nat46 and nat64 are included in firewall policy settings.

  • ippool and ippool6 support NAT46 and NAT64 (when enabled, the IP pool should match a subnet).

  • Central SNAT supports NAT46 and NAT64.

  • add-nat46-route in ippool6 and add-nat64-route in ippool are enabled by default. The FortiGate generates a static route that matches the IP range in ippool6 or ippool for the naf tunnel interface.

Note

Automatic processing of the naf tunnel interface is not supported in security policies.

To configure NAT46 or NAT64 translation, use the standard vip or vip6 setting, apply it in a firewall policy, enable NAT46 or NAT64, and enter the IP pool to complete the configuration.

Note

The external IP address cannot be the same as the external interface IP address.

This section includes: