![Fortinet FortiWAN Handbook Download Page 219](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088219.webp)
NAT
Optional Services
When = All-Time, Source = Any Address, Destination = Any Address, Service = Any,
Translated = 128.227.251.80
WAN link 2:
Bridge mode: One Static IP, the IP on localhost is 125.227.250.10. System adds the default rules to
WAN link 2 as following:
When = All-Time, Source = 125.227.250.10, Destination = Any Address, Service =
Any, Translated = No NAT
When = All-Time, Source = Any Address, Destination = Any Address, Service = Any,
Translated = 128.227.250.10
WAN link 3:
Bridge mode: Multiple Static IP, 125.227.252.100-125.227.252.101 are deployed on localhost,
125.227.252.102-125.227.252.103 are deployed in WAN, 125.227.252.104-125.227.252.105 are deployed in DMZ.
System adds the default rules to WAN link 3 as following:
When = All-Time, Source = 125.227.252.100-125.227.252.101, Destination = Any
Address, Service = Any, Translated = No NAT
When = All-Time, Source = 125.227.252.104-125.227.252.105, Destination = Any
Address, Service = Any, Translated = No NAT
When = All-Time, Source = Any Address, Destination = Any Address, Service = Any,
Translated = 128.227.252.100
WAN link 4:
Bridge mode: PPPoE, system adds the default rule to WAN link 4 as following:
When = All-Time, Source = Any Address, Destination = Any Address, Service = Any,
Translated = DynamicIP(DHCP/PPPoE)
The last rule translates source IP address of all packets into an IP address (localhost) of the WAN link. The second (or
third) rule from the bottom ignores NAT to packets coming from subnets of the WAN link. Those default rules are
added as the bottom rules to the top-down rule table. They are unable to be deleted and edited, unless the
correspondent deployment of the WAN link changes. The default rules will translate source IP address of a matched
packet into the first of the IP addresses that are assigned to localhost of the WAN link, which normally is a public IPv4
address or global IPv6 address. Therefore, packets with private source address (IPv4) or Link-Local source address
(IPv6) are acceptable to Internet after the NAT process. However, even a packet comes with public source address
(IPv4) or Global source address (IPv6), NAT is also performed if it matches the last rule. NAT default rules are based
on deployment of a WAN link, deployment of LAN is regardless. Set NAT rules manually for advanced applications.
Similarly, system generates default rules for IPv6/IPv4 dual stack WAN links. Take the WAN link 1 above as example,
if a IPv6 basic subnet 2001::/64 is deployed on WAN link 1 and the localhost is 2001::1, system adds the IPv6 default
rules to WAN link 1 as following:
When = All-Time, Source = 2001::/64, Destination = Any Address, Service = Any,
Translated = No NAT
When = All-Time, Source = Any Address, Destination = Any Address, Service = Any,
Translated = 2001::1
FortiWAN Handbook
Fortinet Technologies Inc.
219