NAT: SNAT, DNAT & VIPs

FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)

مقصدObjectiveObjective

اس لیب میں آپ انٹرنیٹ رسائی کے لیے SNAT (پالیسی NAT اور سینٹرل NAT) کنفیگر کریں گے اور اندرونی ویب سرور پبلش کرنے کے لیے VIP (DNAT) بنائیں گے۔Is lab mein aap internet rasai ke liye SNAT (policy NAT aur central NAT) configure karenge aur androoni web server publish karne ke liye VIP (DNAT) banayenge.In this lab you will configure SNAT (policy NAT and central NAT) for internet access and create a VIP (DNAT) to publish an internal web server.

آسان مثالSimple AnalogySimple Analogy

SNAT ایسے ہے جیسے سوسائٹی کا ریسپشن ڈیسک: اندر کے خط (پرائیویٹ IP) ریسپشن کی مہر (پبلک IP) لگا کر باہر جاتے ہیں۔ DNAT/VIP ایسے ہے جیسے اندر کا ایکسٹینشن نمبر جسے باہر سے مین نمبر پر کال کر کے پہنچ سکتے ہیں۔SNAT aise hai jaise society ka reception desk: andar ke khat (private IP) reception ki mohar (public IP) laga kar bahar jate hain. DNAT/VIP aise hai jaise andar ka extension number jise bahar se main number par call kar ke pohanch sakte hain.SNAT is like the society reception desk: inside letters (private IPs) go out with the reception's stamp (public IP). DNAT/VIP is like an internal extension number that outside callers can reach through the main number.

سیٹ اپLab SetupLab Setup

fg-03 والی FortiGate استعمال کریں جس میں LAN-to-WAN پالیسی موجود ہے۔ WAN انٹرفیس port1 = 203.0.113.2۔ اندرونی ویب سرور 192.168.10.10 پر ہے۔fg-03 wali FortiGate istemal karen jis mein LAN-to-WAN policy mojood hai. WAN interface port1 = 203.0.113.2. Androoni web server 192.168.10.10 par hai.Use the fg-03 FortiGate with the LAN-to-WAN policy. WAN interface port1 = 203.0.113.2. Internal web server at 192.168.10.10.

اقداماتStepsSteps

Step 1

پالیسی پر سمپل SNAT آن کریں۔ FortiGate LAN سورس کو آؤٹ گوئنگ انٹرفیس کے IP پر ٹرانسلیٹ کرتا ہے — یہی پالیسی NAT ہے، سب سے عام سیٹ اپ۔Policy par simple SNAT on karen. FortiGate LAN source ko outgoing interface ke IP par translate karta hai — yahi policy NAT hai, sab se aam setup.Enable simple SNAT on the policy. The FortiGate translates the LAN source to the outgoing interface's IP — this is policy NAT, the most common setup.

config firewall policy
    edit 1
        set nat enable
    next
end

🖱️ Policy & Objects > Firewall Policy میں LAN-to-WAN پالیسی ایڈٹ کریں اور NAT سیکشن میں NAT آن کریں۔Policy & Objects > Firewall Policy mein LAN-to-WAN policy edit karen aur NAT section mein NAT on karen.Edit the LAN-to-WAN policy under Policy & Objects > Firewall Policy and enable NAT under NAT.

Step 2

IP پول بنائیں اور پالیسی سے جوڑیں۔ اب LAN ہوسٹس انٹرفیس IP کے بجائے پول کے ایڈریسز پر ٹرانسلیٹ ہوں گے — مفید جب فکسڈ، ٹریس ایبل پبلک IP چاہیے ہوں۔IP pool banayen aur policy se joren. Ab LAN hosts interface IP ke bajaye pool ke addresses par translate honge — mufeed jab fixed, traceable public IP chahiye hon.Create an IP pool and attach it to the policy. LAN hosts are now translated to addresses from the pool instead of the interface IP — useful when you need fixed, traceable public IPs.

config firewall ippool
    edit POOL-WAN
        set startip 203.0.113.20
        set endip 203.0.113.29
    next
end
config firewall policy
    edit 1
        set nat enable
        set ippool enable
        set poolname POOL-WAN
    next
end

🖱️ Policy & Objects > IP Pools میں پول بنائیں، پھر پالیسی میں NAT > IP Pool میں سلیکٹ کریں۔Policy & Objects > IP Pools mein pool banayen, phir policy mein NAT > IP Pool mein select karen.Create the pool under Policy & Objects > IP Pools, then select it in the policy under NAT > IP Pool.

Step 3

سینٹرل NAT موڈ پر تبدیل کریں۔ اب NAT ایک مرکزی ٹیبل میں ڈیفائن ہے اور فائر وال پالیسیز صرف allow/deny فیصلہ کرتی ہیں۔ بہت سی پالیسیز میں یہ مینجمنٹ آسان بناتا ہے۔Central NAT mode par tabdeel karen. Ab NAT aik markazi table mein define hai aur firewall policies sirf allow/deny faisla karti hain. Bahut si policies mein yeh management aasan banata hai.Switch to central NAT mode. NAT is now defined in a central table, and firewall policies only decide allow/deny. This scales better with many policies.

config system settings
    set central-nat enable
end
config firewall central-snat-map
    edit 1
        set orig-addr LAN_NET
        set dst-addr all
        set nat-ippool POOL-WAN
    next
end

🖱️ CLI سے Central SNAT آن کریں (System > Settings میں بھی نظر آتا ہے)، پھر Policy & Objects > Central SNAT میں رول بنائیں۔CLI se Central SNAT on karen (System > Settings mein bhi nazar aata hai), phir Policy & Objects > Central SNAT mein rule banayen.Enable Central SNAT from the CLI (System > Settings also shows it), then create the rule under Policy & Objects > Central SNAT.

Step 4

DNAT کے لیے VIP بنائیں: پبلک 203.0.113.10:80 اندر کے 192.168.10.10:80 سے میپ ہوتا ہے۔ صرف VIP کافی نہیں — WAN-to-LAN پالیسی بھی چاہیے جو VIP تک ٹریفک الاؤ کرے۔DNAT ke liye VIP banayen: public 203.0.113.10:80 andar ke 192.168.10.10:80 se map hota hai. Sirf VIP kaafi nahi — WAN-to-LAN policy bhi chahiye jo VIP tak traffic allow kare.Create a VIP for DNAT: public 203.0.113.10:80 maps to internal 192.168.10.10:80. A VIP alone is not enough — you also need a firewall policy that allows WAN-to-LAN traffic to the VIP.

config firewall vip
    edit WEB_VIP
        set extintf port1
        set extip 203.0.113.10
        set mappedip 192.168.10.10
        set portforward enable
        set extport 80
        set mappedport 80
    next
end
config firewall policy
    edit 2
        set name WAN-to-Web
        set srcintf port1
        set dstintf port2
        set srcaddr all
        set dstaddr WEB_VIP
        set service HTTP
        set schedule always
        set action accept
        set logtraffic all
    next
end

🖱️ Policy & Objects > Virtual IPs میں VIP بنائیں، پھر Policy & Objects > Firewall Policy میں پالیسی سے allow کریں۔Policy & Objects > Virtual IPs mein VIP banayen, phir Policy & Objects > Firewall Policy mein policy se allow karen.Create the VIP under Policy & Objects > Virtual IPs, then allow it with a policy under Policy & Objects > Firewall Policy.

Step 5

ویریفائی کریں کہ SNAT پول اور VIP لوڈ ہیں۔ باہر سے ٹیسٹ کریں: http://203.0.113.10 کھولیں اور اندرونی ویب پیج لوڈ ہونا چیک کریں۔Verify karen ke SNAT pool aur VIP load hain. Bahar se test karen: http://203.0.113.10 kholen aur androoni web page load hona check karen.Verify the SNAT pool and VIP are loaded. Test from outside: browse http://203.0.113.10 and confirm the internal web page loads.

diagnose firewall ippool list
diagnose firewall vip list

تصدیقVerifyVerify

اندر کے ہوسٹس کے نئے سیشنز Forward Traffic لاگز میں NAT کے ساتھ لاگ ہوتے ہیں۔ باہر کے یوزرز VIP کے پبلک IP سے ویب سرور تک پہنچتے ہیں۔Andar ke hosts ke naye sessions Forward Traffic logs mein NAT ke saath log hote hain. Bahar ke users VIP ke public IP se web server tak pohanchtay hain.Inside hosts get new sessions logged with NAT in Forward Traffic logs. Outside users reach the web server through the VIP's public IP.

diagnose firewall ippool list
diagnose firewall vip list

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ VIP بنا لیا مگر باہر سے ویب سرور reachable نہیں۔VIP bana liya magar bahar se web server reachable nahi.VIP created but the web server is unreachable from outside.

✅ VIP صرف ایڈریس ٹرانسلیٹ کرتا ہے — WAN سے VIP آبجیکٹ تک accept پالیسی اب بھی چاہیے۔ چیک کریں کہ پالیسی کا dstaddr WEB_VIP ہے، سرور کا پرائیویٹ IP نہیں۔VIP sirf address translate karta hai — WAN se VIP object tak accept policy ab bhi chahiye. Check karen ke policy ka dstaddr WEB_VIP hai, server ka private IP nahi.A VIP only translates the address — you still need an accept policy from WAN to the VIP object. Check the policy's dstaddr uses WEB_VIP, not the server's private IP.

⚠️ NAT ٹائپ تبدیل کرنے کے بعد ٹریفک غلط پبلک IP پر NAT ہو رہا ہے۔NAT type tabdeel karne ke baad traffic ghalat public IP par NAT ho raha hai.Traffic is NATed to the wrong public IP after switching NAT types.

✅ پالیسی NAT اور سینٹرل NAT ایک ساتھ مت ملائیں۔ ایک موڈ منتخب کریں، پالیسی سے NAT سیٹنگ ہٹائیں اور diagnose firewall ippool list سے ویریفائی کریں۔Policy NAT aur central NAT aik saath mat milayen. Aik mode muntakhib karen, policy se NAT setting hatayen aur diagnose firewall ippool list se verify karen.Do not mix policy NAT and central NAT at the same time. Pick one mode, remove the NAT setting from the policy, and verify with diagnose firewall ippool list.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ پالیسی NAT اور سینٹرل NAT میں کیا فرق ہے؟Policy NAT aur central NAT mein kya farq hai?What is the difference between policy NAT and central NAT?

پالیسی NAT ہر پالیسی پر الگ NAT لگاتا ہے۔ سینٹرل NAT NAT کو الگ سینٹرل SNAT/DNAT ٹیبلز میں رکھتا ہے — فائر وال پالیسی صرف allow/deny فیصلہ کرتی ہے۔ سینٹرل NAT بڑی ڈیپلائمنٹس میں مینجمنٹ آسان بناتا ہے۔Policy NAT har policy par alag NAT lagata hai. Central NAT NAT ko alag central SNAT/DNAT tables mein rakhta hai — firewall policy sirf allow/deny faisla karti hai. Central NAT bari deployments mein management aasan banata hai.Policy NAT puts NAT on the individual firewall policy. Central NAT moves NAT into separate central SNAT/DNAT tables — the firewall policy only decides allow/deny. Central NAT is easier to manage at scale.

❓ ورچوئل IP (VIP) کیا ہے اور کب استعمال ہوتا ہے؟Virtual IP (VIP) kya hai aur kab istemal hota hai?What is a Virtual IP (VIP) and when do you use it?

VIP ایک پبلک IP (اور اختیاری پورٹ) کو اندر کے سرور کے پرائیویٹ IP سے جوڑ دیتا ہے، تاکہ باہر کے یوزرز FortiGate کے پبلک ایڈریس سے سرور تک پہنچیں۔VIP aik public IP (aur optional port) ko andar ke server ke private IP se jor deta hai, taake bahar ke users FortiGate ke public address se server tak pohanchen.A VIP maps a public IP (and optional port) to an internal server's private IP, so outside users reach the server through the FortiGate's public address.