| Description | This article explains how to work around the impossibility of accessing a private IP on the WAN side with PPPoE. This limitation exists because WANs with PPPoE cannot have a secondary IP. |
| Scope |
FortiGate, WAN with PPPoE. Tested on v6.4.8 build1914 | v6.4.10 build2000.
|
| Solution |
Adapt the configuration to limit the source in the rule so the internal clients will be able to reach that private network.
1) Create a Static Route for the network: Go to Network -> Static Routes and select 'Create New'.
2) Create an IP pool: Go to Policy & Objects -> Virtual IPs, select 'Create New' -> 'IP Pools'.
3) Create a Firewall Policy:
Alternatively, create the policies in the CLI with the following commands:
Result:
internal in 10.16.4.56 -> 192.168.1.5: icmp: echo request |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.