Skip to main content
Yac
New Member
May 4, 2025
Question

Static route between 2 fortigates does not work correctly.

  • May 4, 2025
  • 16 replies
  • 2726 views

Hi,

If I summarize correctly, we have 2 sites A and B.

On site A, we have the fortigate which is a NAT router and the ISP's internet connection is connected to the fortigate.
On site A, we have the fortigate which is a NAT router and the ISP's Internet connection is connected to the fortigate's WAN port.
On site B, we have a 2nd Fortigate, and have connected port 1 of Fortigate1 to the WAN1 of the second Fortigate.
On the Lan of the second Fortigate, we've allocated the CCTV cameras, and we'd like to view them from our site A.

Fortigate1 LAN IP address: 172.20.100.1/24

Fortigate 2 LAN IP address: 192.168.1.1/24

Fortigate1 WAN IP address: 10.1.10.1

Fortigate2 WAN IP address: 10.1.10.2

16 replies

Toshi_Esumi
SuperUser
SuperUser
May 4, 2025

FortiGate2's WAN IP should be inside of 172.100.0/24 then it's GW should be .1.

Toshi

Toshi_Esumi
SuperUser
SuperUser
May 4, 2025

Also, you need to/must have a site-to-site IPsec vpn or something else to reach LAN side of Site B from LAN side of Site A. Then proper static routes are needed on both sides through the tunnel. You haven't showed them yet.

Toshi

Atul_S
Staff & Editor
Staff & Editor
May 4, 2025

Hi Yacer,

 

Its best if you could share the static routes configured for your setup, along with the  correct NAT mapping on both FGT and the correct security policy defined. 

 

Thanks,

dingjerry_FTNT
Staff
Staff
May 5, 2025

Hi @Yac ,

 

1) "On site B, we have a 2nd Fortigate, and have connected port 1 of Fortigate1 to the WAN1 of the second Fortigate."

 

How did you connect FGT1 port1 to the FGT2 WAN1?  MPLS? Via a switch or router in the middle?

 

2) What is the IP assigned to the FGT1 port1?  There is no such info.

 

So based on your description, the network diagram seems like below:

 

ISP --> WAN (10.1.10.1) <--> FGT1 <--> Port1   ......    WAN1 (10.1.10.2)<-> FGT2 <-> LAN (192.168.1.1/24) <-> CCTV cameras

 

I don't know where I can put this info in this diagram:   Fortigate1 LAN IP address: 172.20.100.1/24

Yac
YacAuthor
New Member
May 5, 2025

DIAGRAM FORTIGATE.jpg

 

Here's the diagram to summarize

dingjerry_FTNT
Staff
Staff
May 5, 2025

Thank you, and this is much better and it proves that this statement is incorrect:

 

Fortigate1 WAN IP address: 10.1.10.1

 

It is port4 interface with the IP address 10.1.10.1

I assume that the CCTV cameras have the IPs from the 192.168.1.0/24 subnet, correct?

 

Do they allow source IP from IPs other than the 192.168.1.0/24 subnet?  

 

1) On FGT1, create a static route for the 192.168.1.0/24 subnet with interface port4 and default gateway 10.1.10.2;

 

2) On FGT2, create a static route for the 172.20.100.0/24 subnet with interface wan1 and default gateway 10.1.10.1;

 

3) Create appropriate firewall policies on FGT1 and FGT2 respectively.  If CCTV cameras do not like source IP other than 192.168.1.0/24 subnet, you may enable NAT in the inbound firewall policy on FGT2.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!