Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
0skarprez
New Contributor

2 Fortigates interconnection

Hello all, 

 

I hope you can help me, I have 2 different networks at my office, they do not have any interconnection betweem them, please see the diagram, now I need host A to reach host B locally, and to reach host C through the MPLS circuit. since at my coreswitch 1 I have 5 different vlans, and just one of them needs to reach the two remote hosts, I belive that the best and secure way to do this is to interconnecting the 2 fortigates. What do you think? I am not sure how to do this, any help is very appreciated.

 

Thank you all

 

 

1 Solution
sw2090
Honored Contributor

First of all you will need some (physical) connection btween those three. That could e.g. bei a Site2Site IPSec bettween the FGT or a wired connection between them.

Once you have that you could create routing and policies on the FGT for the traffic you want to flow between the sides.

 

Id eg. do S2S from FGT 1 to FGT2 and from FGT1 to FGT 3.

Then create on FGT 1 routing for subnet or host B and C with dst iface the corresponding S2S.

FGT 2 and 3 need to have a route to Subnet/Host A.

Then all three need policies to allow the traffic. You will need a policy for each subnet/vlan.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

View solution in original post

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
1 REPLY 1
sw2090
Honored Contributor

First of all you will need some (physical) connection btween those three. That could e.g. bei a Site2Site IPSec bettween the FGT or a wired connection between them.

Once you have that you could create routing and policies on the FGT for the traffic you want to flow between the sides.

 

Id eg. do S2S from FGT 1 to FGT2 and from FGT1 to FGT 3.

Then create on FGT 1 routing for subnet or host B and C with dst iface the corresponding S2S.

FGT 2 and 3 need to have a route to Subnet/Host A.

Then all three need policies to allow the traffic. You will need a policy for each subnet/vlan.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors