Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

Jeroen_Bismans_FTNT

Fortigate with NAT device and dynamic IP

Hello

We have a POC with several FGT's, all behind NAT devices with dynamic IP's.
The WAN IP on the FGT is static but the NAT device in front has a dynamic IP. They will connect to an externally hosted FMG. 

I did some tests and the FMG seems to be capable of handling the public IP changes.
It takes between 5-6 minutes after an IP change for the FMG to see the change.

Is there some more info on this?
I would like to be able to explain how the "tunnel" between the FGT and FMG works.
Currently I know it's using TCP 541 with SSL/TLS encryption: High

Algorithms are: DHE-RSA-AES256-SHA:AES256-SHA: EDH-RSA-DES-CBC3-SHA: DES-CBC3-SHA:DES-CBC3-MD5:DHE-RSA-AES128-SHA:AES128-SHA

Can we speed up the failover time? What is the interval it uses to connect or update the status?

Any info/detail on the connection is welcome.

Thank you!

 

1 Solution
jpforcioli_FTNT

Hi,

You should have a look at the doc attached to Mantis #0282493.

Could you also please let us know your method to measure those 5-6 minutes?

Best Regards.

Jean-Pierre FORCIOLI

View solution in original post

2 REPLIES 2
jpforcioli_FTNT

Hi,

You should have a look at the doc attached to Mantis #0282493.

Could you also please let us know your method to measure those 5-6 minutes?

Best Regards.

Jean-Pierre FORCIOLI
Jeroen_Bismans_FTNT

Thank you very much for this info.
It looks very useful, I will check it in further detail.

The 5-6 minutes I measured in a not so accurate method.
I simulated the NAT with another FGT.

  1. I changed the IP on the NAT device and checked how long it took to change in the device manager on the FMG.
  2. I changed the IP on the NAT device and checked the session table to see when the managed FGT tried to connect again.

 Both were around 5 minutes.