Skip to main content
bendsley
New Member
April 23, 2018
Question

FortiGate in AWS

  • April 23, 2018
  • 9 replies
  • 11028 views

I'm trying to get a FortiGate setup and I have an outside subnet and an inside subnet setup on it.  From AWS, I have multiple subnets setup and wish for each of those to start going through the FortiGate. 

 

Can I set these up as VLANs on the FortiGate or do I need to enable a port for each one?  Currently, I have a medium tier FG setup, but it only allows me two interfaces, internal and external.

 

I cannot seem to get the correct configuration where I can have a test machine (instance) in a different subnet/VLAN where it will ping the FGT.

 

Example:

Outside: 172.250.254.254

Inside: 172.250.253.254

Test VLAN: 172.250.250.254 (IP for VLAN interface)

Test Machine 250: 172.250.250.250 (Linux instance)

Test Machine 253: 172.250.253.250 (Linux instance)

 

From Machine 253, I can ping the IP for the inside interface at 172.250.253.254.

From Machine 250, I cannot ping the IP for the VLAN 250 interface at 172.250.250.254.

 

On the Fortigate in cli, I can ping both the inside interface ip and the VLAN 250 interface ip.

 

I really can't find much in the way of how this can be setup with more than one subnet.

    9 replies

    emnoc
    New Member
    April 23, 2018

    diag arp list but  are you sure of the VPC subnets or is this a typo

     

     

    Inside: 172.250.253.254 Test VLAN: 172.250.250.254 (IP for VLAN interface) Test Machine 250: 172.250.250.250 (Linux instance) Test Machine 253: 172.250.253.250 (Linux instance)

    bendsley
    bendsleyAuthor
    New Member
    April 23, 2018

    Yes, correct about those.

    In the VPC, I have subnets 172.250.253.0/24 and 172.250.250.0/24

     

    Inside IP of FGT: 172.250.253.254.  Any instance machine I put into the 172.250.253.0 subnet, it works fine.  I can ping both ways.

     

    IP of VLAN 250 on FGT: 172.250.250.254.  This is part of the inside port (port2).  Any instance machine I put into 172.250.250.0/24, I cannot ping the VLAN 250 gateway IP (172.250.250.254).

     

     

    I guess I'm wondering, do I need to setup my inside IP to cover all of the subnets I need, and then I can VLAN on it...and set my route tables up to include all of the IPs I need?  Right now, the AWS route table for both of those subnets point to the inside interface (port2) on the FGT instance.

    emnoc
    New Member
    April 23, 2018

    In your VPC do you have two subnet? if that's truly the case than you need interfaces in the AWS instance. How would the AWS-FGT know about the 2nd  subnet if it did not have a route  to it or a 2nd interface ?

     

    Ken

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!