Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
v20100
New Contributor III

Access to Management port from LAN

Hi

I have 2 new 200D configured in HA. have configured mgt ports on 10.10.1.x/24 subnet.

Lan configured on port1 on 10.10.2.x/24 subnet

 

I cannot access the mgt IP of the firewalls from the lan. If I plug a laptop on the 10.10.1.x/24 subnet switch, no problems.

the admin user can access from everywhere. I tried to add a policy rule from lan to mgt, but mgt does not show as an interface choice.

 

I can still administer the firewalls from the lan using the IP of the firewall on the 10.10.2.x/24 subnet, but because the firewalls are in HA, I cannot access each firewall separately.

 

What do I need to setup to be able to access the mgt ports from the lan?

Alternatively, is there a way to assign an IP from the lan subnet to the mgt port?

 

Thanks

5 REPLIES 5
ede_pfau
SuperUser
SuperUser

Your second thought is the easiest way to go: you can assign an IP address to a mgmt port even if that subnet is already assigned to another port (e.g. 'internal'). That's how I configure HA cluster members. The mgmt port address is not replicated/synchronized across the cluster.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
v20100
New Contributor III

Hi

unfortunately, it does not seem to work. When I enter the IP address (ie 10.10.2.50/255.255.255.0) is tells "Conflicts with port1 subnet'

 

I tried to select and unselect 'Dedicated Management Port', but it does not make any difference.

 

Any other ideas?

 

Thanks

ede_pfau

The duplicate address feature will only work with dedicated mgmt ports. Maybe you have to reboot the FGT after switching the option.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
v20100
New Contributor III

I see. I would need to have separate IP on each unit. Not sure if it is a good thing after all.

As we are managing from the time being via the lan interface IP, I think I will leave it as it is, as it does not seem to have an impact not being able to manage via the mgt ports.

ede_pfau

There are advantages to this feature, as you can use all GUI tools to monitor the slave unit. For instance, current load or HA sync status, refreshing the config file backup copy on the local USB stick etc. etc.

But of course you can live without quite well.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors