Skip to main content
Fortimaster1
Explorer
December 16, 2025
Question

DMZ Default route for servers

  • December 16, 2025
  • 9 replies
  • 834 views

Hi all,

I'm changing some things on my network. Currently (in summary) I have a DMZ with two Fortigate and one switch. The servers and the firewalls connect to the switch.

Each server has 2 static routes

1º)Default route --> IP address of the external fortigate.

2º)Route to reach internal private addresses -->Internal fortigate.

 

I'm thinking about configure the servers with just one default route for the switch that connects them. This switch, sends traffic to external or internal firewall and Doesn't route any traffic between DMZ network and other networks. 

Server-->Switch-->Firewall Internal / Firewall External.

 

If I use a firewall as default gateway for servers, some times the traffic will have more hops than I want. Example

Traffic from server DMZ, to server Datacenter:

                  -ServerDMZ-->switch(layer 2)-->firewall external-->Switch another time-->Firewall internal.

 

What do you think about using a single default route to layer3 switch, that interconnects everything and it doesn't route between DMZ and other networks. It only sends traffic to internal or external firewall. It's an acceptable design to a DMZ in your opinion?

Thanks

 

9 replies

Toshi_Esumi
SuperUser
SuperUser
December 16, 2025

Doesn't the "server Datacenter" have a private IP to be reached via the 2nd static route on the DMZ servers? Then it shouldn't go to the external FGT. 

Toshi

Fortimaster1
Explorer
December 16, 2025

Thanks ¡¡ I'm talking about DMZ servers.

Yes, actually they have two static routes: Default (external firewall) and 2nd static route to the datacenter servers (internal firewall).

I would like to use only one default route (to the switch that connect both firewalls and servers).

Toshi_Esumi
SuperUser
SuperUser
December 16, 2025

So you're saying you want to eliminate any other static routes on the DMZ servers? If your switch is a L3 switch, yes, you can. Then the switch needs to have 1) default route to the external FGT, and 2) those necessary static routes to the internal FGT, instead.

Toshi

AEK
SuperUser
SuperUser
December 16, 2025

Your suggested design seem to work fine and seem better than the existing. But the first question I'd ask when it comes to design is: does it follow standards?

AEK
Fortimaster1
Explorer
December 16, 2025

AEK,I'm not sure if he follows them. That's why I'm asking if it's a reasonable design, taking into account all aspects and comparing it to the current one (with some static routes in the servers).

AEK
SuperUser
SuperUser
December 17, 2025

I'm also not sure, but as long as the L3 switch doesn't route traffic between VLANs (without filtering) then you should be safe.

On the other hand a standard design that I always follow and I'm always happy with it is to attach the DMZ to the edge firewall only, even if the traffic transit through 2 firewalls instead of one. It is true that it is less performance but this little performance difference was never required in my case.

You know in enterprise environment we should always follow standards, otherwise one day some expert or some audit will find strange things and will ask who did this s***?!! (sorry for the expression)

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.