Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Hassan-wahab
New Contributor II

AWS Fortigate WAN IP

Hi,
I've deployed a Fortinet Nextgen Firewall in AWS. Initially, the WAN interface IP is set to a local IP within the public subnet. However, when I attempt to change it to the actual public IP, I lose connection to the firewall entirely. As a result, I can no longer access it via HTTPS or SSH. Can anyone assist me in resolving this issue? My objective is to utilize the static public IP assigned by AWS for the WAN interface.

Thanks

1 Solution
ozkanaltas
Valued Contributor III

Hello @Hassan-wahab ,

 

On AWS environment, you cant give public ip address directly to Fortigate interface. You need to configure NAT or assign elastic ip address to Fortigate private address on AWS.If you want to use external ip more than one. Firstly, you can configure secondary ip on Fortigate.After that you can assign external ip address to this private ip. Fortigate should be use private ip address on interface.

 

You can review this document about assign external ip to Fortigate private ip.

 

https://docs.fortinet.com/document/fortigate-public-cloud/7.2.0/aws-administration-guide/223744/assi...

 

https://community.fortinet.com/t5/Blogs/Adding-Elastic-IPs-to-AWS-FortiGate-to-be-used-as-VIPs/ba-p/...

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
2 REPLIES 2
ozkanaltas
Valued Contributor III

Hello @Hassan-wahab ,

 

On AWS environment, you cant give public ip address directly to Fortigate interface. You need to configure NAT or assign elastic ip address to Fortigate private address on AWS.If you want to use external ip more than one. Firstly, you can configure secondary ip on Fortigate.After that you can assign external ip address to this private ip. Fortigate should be use private ip address on interface.

 

You can review this document about assign external ip to Fortigate private ip.

 

https://docs.fortinet.com/document/fortigate-public-cloud/7.2.0/aws-administration-guide/223744/assi...

 

https://community.fortinet.com/t5/Blogs/Adding-Elastic-IPs-to-AWS-FortiGate-to-be-used-as-VIPs/ba-p/...

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
mpeddalla
Staff
Staff

Hello @Hassan-wahab  ,

 

Thank you for contacting the Fortinet Forum portal.

As mentioned by @ozkanaltas we cannot have direct public wan IP on the interface AWS hosted fortigate.

Please refer to the below document for guidance :

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/e129c4eb-867b-11eb-9995-005056...

 

-Feel free to open a support ticket with AWS on how to deploy the network interfaces and attach them to Fortigate and also support requests on Fortigate if you still have issues.

 

Best regards,

Manasa.

 

If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.

Manasa
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors