Issue with Comcast EDI on Fortigate 200D v5.6.3
Hello, many confusing posts and discussions regarding the proper way to handle Comcast's EDI with /30 PTP network for connection to the Ciena Router and the public user block provided with the same service. In our case it's a/28 block of useable ips. We have also put a L3 switch in front of the Fortigate and connected the Ciena PTP to the switch on one vlan, and provided for the useable ips on another vlan. I have been wanting to eliminate the L3 switch in between and directly connect the Fortigate WAN1 port to the Ciena, which I have done, but want to use the other block of ip's. I setup Port 14 (was available, no other reason) on the FG with one of the ip addresses from that block and have connected a device to that port with another ip from that block. I can ping the FG port from my laptop while on the lan. I have created a policy that allows all traffic from the wan side to the port14 interface with the public ip address on it but I can not ping that address from the wan side. My understanding was that the /28 block of useable ip addresses was reachable with out any other configuration magic. Does anyone have a clear, basic guide to helping me understand all the nuts and bolts required to be able to access that /28 block?
The connected device can reach the FG but traffic won't go out wan1. I'm getting confused with all the different suggestions including the use of VIPs, IP Pools, others have talked about proxy arp or static arp settings and I think it's causing me to over complicate things.
Any help or guidance sincerely appreciated.
Brad
