Skip to main content
AUT_Maverick
Visitor III
July 25, 2023
Solved

VIP Behavior

  • July 25, 2023
  • 1 reply
  • 1710 views

I have created VIP objects on the Fortigate. Since I am in the process of replacing another firewall with the Fortigate. Now I have experienced the following phenomenon. Every request is sent to the Fortigate and not to the other firewall running in parallel. How can this be that the Fortigate gets these requests although I have not yet created a policy just the VIP Objects?

Best answer by saneeshpv_FTNT

Hi,

 

Once you create a VIP object in the FortiGate it will start performing ARP reply as this VIP now belongs to Fortigate. You may disable ARP for that VIP.

# config firewall vip
    edit <name>
        set arp-reply disable (default: enable)
    next
end

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-ARP-reply-setting-in-Virtual-IP-IP-Pool/ta-p/192527

 

Best Regards,

 

1 reply

saneeshpv_FTNT
Staff
Staff
July 25, 2023

Hi,

 

Once you create a VIP object in the FortiGate it will start performing ARP reply as this VIP now belongs to Fortigate. You may disable ARP for that VIP.

# config firewall vip
    edit <name>
        set arp-reply disable (default: enable)
    next
end

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-ARP-reply-setting-in-Virtual-IP-IP-Pool/ta-p/192527

 

Best Regards,

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!