Skip to main content
LEO08
New Member
December 20, 2016
Question

Serparate WAN ports

  • December 20, 2016
  • 5 replies
  • 7159 views

We are using a Fortigate 60D in our work place. The 60D is used as our UTM/core router and is using one WAN link to provide internet access. The company plans to add a second firm in the current location. The new firm will have a separate internet connection for its users. The plan is to setup 2 VLANS, one for the current business and the second for the new firm and create my policies according to business’s needs. My question is can(and how) I setup the fortigate to route internet traffic out separate WAN interfaces according to the VLANs being used?

 

Thanks

    5 replies

    neonbit
    New Member
    December 29, 2016

    This can be done with policy based routes. You can create a policy based route so everything from business-vlan goes out of WAN1 and everything from newfirm-vlan goes out of WAN2.

     

    This is configured under Network > Policy Routes and would look something like this:

     

    MikePruett
    New Member
    December 29, 2016

    Here is a good link to read about Policy Based Routing

     

    http://docs.fortinet.com/...ced%20Routing%2052.pdf

    ede_pfau
    SuperUser
    SuperUser
    January 1, 2017

    IMHO a cleaner way with less maintenance in the future would be to enable VDOMs on the FGT and assign one to each firm. That's exactly why there are VDOMs. Completly separate policies, default routes etc.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!