Skip to main content
Musab
New Member
September 21, 2018
Question

Connection Test

  • September 21, 2018
  • 2 replies
  • 4454 views

Hello everyone,

 

I am wondering if FortiGate can have a point-to-point connection with a Cisco router using /31 subnet. And if it does, what is the protocol to enable it? Or is it the usual configuration(default gateway, etc.).

 

Thank you.

    2 replies

    ede_pfau
    SuperUser
    SuperUser
    September 21, 2018

    In general yes, but IMHO you need a /30 mask. Connection will be plain routed, VLAN, IPsec VPN,...whatever you need.

    As the FGT drops traffic from unknown sources you may have to make external networks "known" by installing static routes.

    Toshi_Esumi
    SuperUser
    SuperUser
    September 21, 2018

    We use /31 on FGTs at many places like internal interconnections per customer to save IPv4 public IPs. There were some minor bugs related to /31 subnets in the past but those were with 5.2.x. They fixed them. We migrated most of our FGTs to 5.4 by now and planning to go up to 5.6.6 soon. So far I'm not aware of any issues.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!