Skip to main content
jbrowne
New Member
January 3, 2019
Question

internal routing multiple subnets 1 physical port

  • January 3, 2019
  • 9 replies
  • 15404 views

In the past, I setup a FG100D with multiple internal subnets by using multiple physical ports on the Fortigate and assigning the IPs to those ports as gateways, so each internal subnet could talk to each other.

 

I'm setting up a FG100D at a different company with similar needs.  I was trying to make it simpler by using a single physical LAN port on the Fortigate - possible ?

 

subnets=  192.168.1.0 ,  192.168.8.0 , 192.168.37.0 , 192.168.41.0   

each having a gateway of .x.250  (192.168.1.250....etc....)

 

These should each have access to the other.

And these should each have access to the WAN port.

 

Must I use multiple LAN ports ?

thanks.

    9 replies

    Silver
    New Member
    January 3, 2019

    Hello,

     

    Yes this can be achieved by using sub interface. 

    Thanks

    Dave_Hall
    New Member
    January 3, 2019

    If the company's network is segmented by department, you may be better off using vlans on the physical LAN port, assuming you are able to implement/configure vlans on the network switches and/or devices directly. 

     

    If the company is small and/or does not see a lot of network traffic, you could just create a class B or classless subnet at the private level (eg. 10.10.x.x or 192.168.x.x).

     

    If you need to have multiple subsets on a physical interface, you could create/bind secondary IPs to an interface and use hairpin policies to route traffic.  See KB FD30118.  See also FD30014 regarding overlapping subnets.

     

    Personally, I would use vlans if possible or multiple physical ports.

    jbrowne
    jbrowneAuthor
    New Member
    January 3, 2019

    @Silver - thanks for suggestion.

     

    @Dave Hall  - I tried the secondary IPs (KB FD30118) - but it didn't seem to work.

     

    I'm trying to make the Fortigate's setup as simple as possible with as few steps.

     

    I was also looking at https://cookbook.fortinet.com/using-zones-to-simplify-firewall-policies-56/

    but haven't finished the steps yet.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!