FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
sfernando
Staff
Staff
Article Id 378643
Description

This article provides information concerning Fortinet products with wireless modems and their behavior which are used to connect wireless WAN connections in different environments. 

Scope

FortiGate with wireless modems.

Solution

A FortiGate with wireless modem has a separate wireless modem which is used to communicate with the wireless provider. The communication between the wireless provider takes place by providing a DHCP IP to the Modem of the wireless provider. This modem works as a DHCP client as well as a server.

 

When it works as a DHCP client the modem gets an IP address from the wireless service provider. When it works as a DHCP server it provides an IP to the FortiGate for external communication.

 

The below diagram illustrates how this setup works.

 

  • FortiOS( receives a DHCP lease from the modem)---( a DHCP server)Modem in ForiGate (receives a DHCP from the mobile service provider)-------wireless connection-----Mobile service provider.

 

When the modem starts a call to the Mobile operator's DHCP server, the Mobile operator provides an IP and the gateway to the modem. The modem updates its details with this information. Then the FortiOS uses its DHCP demon to request an IP from the DHCP server which is inside the modem and gains an IP and a gateway. 

 

When the connection is successful this DHCP process takes place automatically and provides the FortiOS with IP and Gateway details. The only way to prevent this DHCP process is to disable the WWAN interface.

 

If the user is not required to update the FortiOS with the dynamically received IP and gateway details, it can be done by overriding these details under 'config system lte-modem'.

 

config system lte-modem
(lte-modem) # set override-gateway enable
(lte-modem) # end

 

Once done, the gateway will be overridden with 0.0.0.0 disabling the gateway provided by the Mobile provider.

Contributors