Fortinet Interface Selection WAN, DMZ
Is it mandatory that I chose WAN interface for Outside segment, DMZ interface for DMZ segment. Is there any hard coded settings such as security levels for these interfaces?
Is it mandatory that I chose WAN interface for Outside segment, DMZ interface for DMZ segment. Is there any hard coded settings such as security levels for these interfaces?
They are labels for convenience. You can apply policies and virtual IPs to any interface.
We had an early FortiGate 80C model which has two gigabit WAN ports and a fast ethernet internal switch. I turned the switch into interfaces and used the WAN ports as LAN ports. The internet connection is less than 100Mbps so it seemed like a waste to use a gigabit port. It's slightly confusing as it's still labelled WAN but you can use an alias.
Check if the ports you want to use are connected to a network processor. This will speed up forwarding of packets by offloading sessions from the CPU after initial setup. Larger FortiGates use network processors. Small FortiGates have a system on a chip. Depending on your model and requirements this may affect the interfaces you want to use.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.