FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
HiralShah
Staff
Staff
Article Id 278769
Description This article discusses steps that need to be taken to ensure everything else in a FortiGate setup works as expected after changing the WAN IP.
Scope FortiGate.
Solution

To change the WAN IP to a new IP address, make sure to make changes as follows:

 

Go to Network -> Interface -> WAN interface and provide a new IP address.

 

1st.png

 

Under Network -> Static routes, provide a new gateway IP address on the static route.

 

2nd.png

 

If the WAN interface is a member of an SD-WAN zone, update the Gateway in SD-WAN settings.

Go to Network -> SD-WAN -> SD-WAN Zones.

Select the WAN interface and update the Gateway IP.

 
 

sd-wan.JPG

 

Also, if SSL VPN is used, make sure the FortiClient -> Remote access -> Remote gateway field has been changed with the new WAN IP address.

 

3.png

 

If site-to-site VPN is configured, make sure to change the remote IP address of the remote side of the tunnel to the new WAN IP.

 

4.png

 

Perform this process during a maintenance window to avoid impairing traffic.

Additionally, check if VIPs are being used. If they are used, the WAN IP needs to be changed on VIPs as well.

 

Navigate to  Policy and Objects -> Virtual IPs:

 

VIP.PNG

 

Make sure to change the gateway IP in the policy route as well:

 

policyroute.png

 

 

Make sure to make changes in the link-monitor configuration as well if applicable:

config system link-monitor
    edit “Wan1 Failover”
        set srcintf “wan1”
        set server “8.8.8.8”
        set gateway-ip x.x.x.x 
<---- Provide updated gateway IP information here. 
        set update-cascade-interface disable
    next

end

 

Note: If source-ip was set on self-originating traffic (DNS, FortiGuard, FortiAnalyzer, FortiManager, syslog, etc), update the source-ip with a new IP address.

 

For example:

 

config system dns
    set source-ip 10.9.15.159       <- New WAN IP address.
end

config sys fortiguard

    set source-ip 10.9.15.159       <- New WAN IP address.

end

 

It is possible to check where the WAN IP was previously configured by running the following command, where x.x.x.x is the WAN IP:

 

show | grep -f x.x.x.x

 

wow.PNG