This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.
In order to a DMZ setup or East-West traffic in AWS using FortiGate-VM, you need to change the default gateway of all the hosts to the FortiGate internal interface IP address for each subnet. Obviously, this needs some manual work but using some automation tools or scripts, this can be automated as well. Eventually the manual steps/automation could be avoided when AWS comes up with Policy Based Routing and /or use the ENI IP from the route table as the default-Gateway for the host VM in the corresponding subnets.
 
					
				
				
			
		
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.