Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

CNelson
New Contributor

DMZ set up and Forigate 200D

I am new to Fortigates and trying to understand setting up a DMZ. The first question relates to the physical connections. Do I need an actual physical connection to the DMZ port from the web server or can any of the fortigate lan based ports be used? Second question, what needs to be done to set up the DMZ for virtual servers set up on esxi hosts? We use Vsphere 6.7. I have found directions on setting up the fortigate to use DMZ, my challenge is the physical connection and how this would be set up. Thanks

------------------------------
Chris
Network Administrator
------------------------------
[FirstName] [JobTitle]
[FirstName] [JobTitle]
2 REPLIES 2
PC
New Contributor III

The DMZ from the firewall perspective can be any dedicated port you configure with the IP range for your DMZ, then the firewall rules for your DMZ to and from any other interfaces. At that point you have a physical connection you have to connect into a switch port or possibly direct to a server DMZ interface but most times you will have  switch connected into your virtual infrastructure then you connect your DMZ port into that.    On the virtual side you need to configure your setup to get the DMZ server traffic into the same VLAN you connected your firewall to.

------------------------------
Peter [LastName] [Designation]
Enterprise Engineer, Networking
[CompanyName]
[City] [State]
[Phone]
------------------------------
snanduru_FTNT

Chris, does Peter's response answer your question? If so, please mark it as a "Best Answer"...



MessageImages_TinyMce_79207f30-053f-4eca-bceb-80442a6c93fe.jpg

------------------------------
Swathi
------------------------------
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.