Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.


DMZ Setup and/or East-West Traffic control in AWS

In order to a DMZ setup or East-West traffic in AWS using FortiGate-VM,  you need to change the default gateway of all the hosts to the FortiGate internal interface IP address for each subnet. Obviously, this needs some manual work but using some automation tools or scripts, this can be automated as well. Eventually the manual steps/automation could be avoided when AWS comes up with Policy Based Routing and /or use the ENI IP from the route table as the default-Gateway for the host VM  in the corresponding subnets.