Skip to main content
NETWORK_USER
New Member
July 3, 2014
Question

Integrating Fortigate into existing network

  • July 3, 2014
  • 5 replies
  • 4692 views
Hello, We have a Fortigate 300 C which is not in the default path to the internet. It is connected to the network gateway router and the gateway router policy routes all the traffic going out to the internet to this FG300C. We want to move this firewall behind the gateway router and implement FG HA. We also plan on moving all the IPsec tunnels and NAT from the gateway router to this firewall. I would like some input on what would be the best way to move the firewall behind the gateway with minimal downtime. One way I am thinking of doing it is by connecting the second FG300C(which is right now on the bench as a backup) behind the router and configuring it to allow all traffic through(open policy) to the gateway router. Once I have done this I can move the configurations (ipsec vpns, nat etc) from the gateway router to this firewall behind the router and once I have moved all the configuration that i want to move, I can restrict the policy as required and apply web filtering and remove the other firewall and connect it to this firewall to make HA pair. Do you think this is better then configuring the firewall offline? Thank you.

    5 replies

    rwpatterson
    New Member
    July 3, 2014
    If you have more than one public IP address, I would set the FGT up on a second, and use it that way. You can then roll everyone over at your leisure.
    billp
    New Member
    July 3, 2014
    +1 on Bob' s advice. I have upgraded my Fortigate several times, and I always like to set it up and test it live before replacing an existing/working box. Before cutting over, I run through a written checklist and verify various combinations of settings, logins, filters, etc.
    emnoc
    New Member
    July 4, 2014
    Even better yet, do you even need the network router? Based on what you stated, I see no need for router+firewall. Could be one less device and/or you can even reposition the router to do something else imho.
    ede_pfau
    SuperUser
    SuperUser
    July 4, 2014
    Placing a Fortigate as VPN gateway behind a router (i.e. into a transition network) is troublesome. A VPN gateway needs a public IP address, right? just my 2 ct.
    rwpatterson
    New Member
    July 4, 2014
    ORIGINAL: ede_pfau Placing a Fortigate as VPN gateway behind a router (i.e. into a transition network) is troublesome. A VPN gateway needs a public IP address, right? just my 2 ct.
    Or a pass through from the gateway device.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.