Skip to main content
mbebwe
Visitor III
March 2, 2023
Solved

use another public ip on WAN interface

  • March 2, 2023
  • 1 reply
  • 1166 views

Hi,

 

We have small public IP (/29) network from our provider, but only one public IP is in use, on External (WAN1) interface. We need to use another public ip, so the only way is add it as secondary to same WAN1 interface? 

 

Also if it's true, don't understand, how then to create a policy to allow, for example, doing NAT through new public ip to internal network ? When I create a new policy with Incoming Interface=WAN1 does it matter which public ip will be using ? 

 

FG100F with fw 7.2.3

Best answer by Yurisk

Hi, 

you do NOT need to put this other IP address on the WAN interface as secondary or in any other way. Just use it in appropriate places:

 

  • For Source NAT of outgoing LAN to Internet connections use as Dynamic IP Pool when configuring a rule
  • FOr Destination NAT for incoming from Internet to LAN VIPs, just use this IP in configuring VIP as if it is known to Fortigate already, just make sure not to limit this VIP to a specific interface when creating it, leave the default any.

You do need to use additional IP as secondary on an interface in specific cases - like taking part in dynamic routing protocols, using for DHCP, few more, but not in your case.

1 reply

Yurisk
SuperUser
YuriskAnswer
SuperUser
March 2, 2023

Hi, 

you do NOT need to put this other IP address on the WAN interface as secondary or in any other way. Just use it in appropriate places:

 

  • For Source NAT of outgoing LAN to Internet connections use as Dynamic IP Pool when configuring a rule
  • FOr Destination NAT for incoming from Internet to LAN VIPs, just use this IP in configuring VIP as if it is known to Fortigate already, just make sure not to limit this VIP to a specific interface when creating it, leave the default any.

You do need to use additional IP as secondary on an interface in specific cases - like taking part in dynamic routing protocols, using for DHCP, few more, but not in your case.

yurisk.info - all things Fortinet blog, no ads
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!