Benefits and limitations of the FULLNAT mode
Key Benefits
-
Simplified routing: Compared with DNAT mode, FULLNAT mode does not require the back-end server to configure FortiADC as its default gateway.
-
Full path control: FortiADC handles both directions of traffic.
-
Strong IP hiding:
-
Client never sees the real server IP.
-
Server never sees the client IP.
-
Limitations
FULLNAT mode is not suitable for applications that require native client IP visibility, as it replaces the source IP (client IP) with an address from FortiADC’s source NAT pool.
However, FortiADC provides a setting that allows it to insert the client IP into the forwarded request. Refer to "Preserving Client IP" in Key considerations of network settings in FULLNAT mode.