Skip to main content
theArties
New Member
January 9, 2020
Solved

Separating a WAN subnet into Multiple Ports

  • January 9, 2020
  • 5 replies
  • 6287 views

Hi all, 

 

Would like to know whether there's a workaround for this. 

Currently a /29 WAN subnet is created on a WAN 1. e.g. 202.188.1.130/29. Gateway is 202.188.1.129.

I want to separate a particular IP out e.g. 202.188.1.132 and connect it to another port e.g. Port 15 for SSL-VPN purpose. 

By default, under the SSL-VPN settings, the box will only listen on the WAN 1 IP i.e. 202.188.1.130:443.

 

How can I make the box to listen to 202.188.1.132 for the SSL-VPN. 

 

Thank you in advance for your guidance. 

 

 

 

 

    Best answer by ShawnZA

    In the link I pasted they guy actually forwards it to his primary extarnal IP, so probably not what you are looking for.

     

    You could also create a loopback interface, and assign any internal IP to it, like 10.40.1.1/30, or just a /32 as you only need one IP

     

    Then create a VIP address with your second external IP and forward it to the IP you specified for the loopback on port 443

     

    Then in the VPN settings you select the new loopback interface as the listening interface. I have done setups like that for IPSEC VPN so I am sure it should work for a SSL VPN setup.

    5 replies

    ShawnZA
    New Member
    January 9, 2020

    You will not be able to set a IP on another interface that is already part of the /29 on your WAN1.

     

    You could break up the /29 in two /30's, but would need extra config on the next hop router as well, and a switch in between if there are no other ports available on the next hop.

     

    You could also do a VIP as per this thread but don't think that's what you are looking for as the original IP will also still be listening for VPN requests unless you block it...

     

    [link]https://forum.fortinet.com/tm.aspx?m=111523[/link]

     

     

     

    theArties
    theArtiesAuthor
    New Member
    January 9, 2020

    Hi ShawnZA, 

     

    Thanks for your time. 

     

    I read thru the link and did a check on the current box. 

    Silly question: what should the mapped IP be? the LAN IP for the box? 

     

    Thanks.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!