Using the GUI to configure NAT/Route mode
To configure DNS settings
- Log into the FortiController GUI.
- Go to Load Balance > Status and select the Config Master icon beside the primary worker, which is always the top entry in the list.
-
Log into the worker GUI.
You can also connect to the worker GUI by browsing directly to the External Management IP/Netmask. - Go to System > Network > DNS and configure DNS settings as required.
To configure an interface
- Go to Virtual Domains > root.
- Go to System > Network > Interfaces and Edit an interface (for example, fctrl/f1).
- Configure the interface as required, for example set the Addressing Mode to Manual and set the IP/Netmask to 172.20.120.10/255.255.255.0.
- Select OK.
- Repeat for all interfaces connected to networks.
To add a default route
-
Go to Router > Static and select Create New and configure the default route:
Destination IP/Mask 0.0.0.0/0.0.0.0 Device fctrl/f1 Gateway 172.20.120.2 - Select OK.
To allow users on the internal network to connect to the Internet
-
Go to Policy > Policy > Policy and select Create New to add the following security policy.
Policy Type Firewall Policy Subtype Address Incoming Interface fctrl/f2 Source Address all Outgoing Interface fctrl/f1 Destination Address all Schedule always Service ALL Action ACCEPT - Select Enable NAT and Use Destination Interface Address.
- Select other security policy options as required (for example, add Security Profiles).
- Select OK.