Skip to main content
MEAMEM
New Member
September 8, 2018
Question

transparent fortigate firewall best practice with two ASA configured in failover mode

  • September 8, 2018
  • 0 replies
  • 1656 views

i have a setup where i have two ASA firewalls facing the wan in failover mode, and between the core switch and the ASAs i have fortigate running 5.4.5 OS in transparent mode, i had ipv4 virtual pairs but they consume a lot of memory, so i wanted  to minimize the load over the memory and changed to IPv4 policies only, but a lot of rules sometimes match implicit deny cause traffic is sent to mgmt port.

 

"ASA1 on interface 12 on fgt , ASA2 on interface 10 on fgt , core switch is connected on interface 9 and 11 traffic coming from vpn users from ASAs they match implicit deny if i don't chose in the destination interface any. can i somehow force all the traffic coming from 12 and 10 to go only to 9 and 11 without using virtual pair and vice versa.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!