Skip to main content
mcdaniels
New Member
January 12, 2018
Question

SOLVED: Main IP / additional subnet / only one port

  • January 12, 2018
  • 11 replies
  • 18842 views

Hi Forti-Gurus ;)

 

I have got a Forti VM. The WAN-Port of the Forti (IP 62.1.2.3) is connected to a Cablemodem (=GW: 62.1.1.1).

There are a hand full of policies which define how to handle outgoing and incoming traffic (VIP, PAT, NAT).

 

Now we got an additional subnet from our provider, which is used via the same Cablemodem. These IPs are not in the 62.1.1.1 subnet. Lets say an IP from the additional subnet is 195.3.3.3.

 

We would like to configure a VIP / PAT which says: If there is a request via WAN to the IP 195.3.3.3 use VIP / PAT to connect to a server in the DMZ (for example: 10.0.0.3).

 

The Problem: We can do this with the 62.1.2.3 - IP, but the IPs from the Subnet cannot be used. (No answer, even when setting up policies with VIP / PAT.)

 

How can I make the Fortigate to react to the IPs from the additional Subnet. There is only one WAN Port, only one connection to the cablemodem.

 

Thanks a lot!

 

    11 replies

    rwpatterson
    New Member
    January 12, 2018

    Try adding a second IP to the WAN port on that second subnet. That is a shot in the dark. There should be a route at your provider's router back to your router with a good IP address or subnet.

    mcdaniels
    mcdanielsAuthor
    New Member
    January 12, 2018

    Hello,

    thanks for the answer.

     

    If I give the WAN-Port one of the subnet-ips as secondary IP and tick "Ping", I cannot ping this IP.

     

    I assume that it should reply to the ping, if it would work that way.

     

     

    tanr
    New Member
    January 12, 2018

    Just to clarify, the cable modem only provides you a single port?  Or is it that you only have a single port available from the Forti VM?

     

    If the cable modem only provides a single port, how is the ISP separating out the subnets for it?  Are they using vlans?  If they're using tagged vlans (at least a tagged vlan for the new IP) they you can just create matching vlans on your wan interface.

    dmcquade
    New Member
    January 13, 2018

    The ISP is probably routing the additional subnet to the Cable modem. If you can manage the Cable modem, you can set a static route for the new subnet pointing to the Firewall's WAN address. You may also be able to request your provider to route the subnet to the firewall's address.

     

    HTH

    d

    mcdaniels
    mcdanielsAuthor
    New Member
    January 15, 2018

    Hi,

    yes, the provider routes the subnet to the "main ip". This ip is set up on the Foritgates WAN1.

    If I set up VIP which does DNAT (subnet IP -> LAN) it works.

    But the Server on the LAN uses the default route (which points to another ISP, and is connected to WAN2).

     

    My Question is: How can I do SNAT, so that the server appears with the subnet-ip when connecting to the internet?

     

    Do I have to use IP-Pools in connection with an outgoing policy?

    mcdaniels
    mcdanielsAuthor
    New Member
    January 15, 2018

    Ok, I came to the following solution now.

    1.) Set up VIP (direction WAN1 -> LAN means: Subnet-IP:80 -> LAN-Server:80)

    2.) Set up policy for this VIP (WAN1 - LAN)

    3.) As there are 2 ISPs connected to the Firewall and I would like the LAN-Server to use the Subnet-IP  (WAN1-Port) when connecting to the internet I set up a policy route which says: Connection from LAN -> Address of Server -> Use WAN1-Port + GW. (Now the server appears with the main-ip to the internet, not the subnet-ip).

    4.) To make the server appear with the subnet-IP to the internet, I set up an ip-pool (with the subnet - ip).

    5.) Finally I created a policy: (direction LAN : IP of Server -> WAN -> NAT -> choose the IP Pool -> Activate NAT.

     

    Seems to work.

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!