Hi,
I currently have a Fortigate with a /29 public IP pool on my WAN interface. I have requested more IP addresses from my ISP.
I need some help to determine the best configuration scenario for an ongoing installation. Here are the details provided by our supplier:
Direct Routing: The supplier suggests that the IP packs be directly routed to our equipment. For this, I need to provide them with the IP addresses of our equipment for our three sites.
Secondary Configuration: Another option is to configure the IP packs as secondary on the LAN of their routers.
I would like to know:
Thank you in advance for your advice and feedback!
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If they route the new public IP space through the existing link as the next hop your FGT, then you just need to configure the VIPs ( DNAT ) / IP Pool ( SNAT ) and the firewall rules for the traffic on the FGT.
Toshi
Thank you,
Yes I want to use VIP and map local device. I think first scenario is the better.
What I have to do in Fortigate? It's the first time I'm doing this.
If they route the new public IP space through the existing link as the next hop your FGT, then you just need to configure the VIPs ( DNAT ) / IP Pool ( SNAT ) and the firewall rules for the traffic on the FGT.
Thank you,
I will try this!
Created on 05-22-2024 09:59 AM Edited on 05-22-2024 09:59 AM
I would agree. For the second option, you would waste totally 3 IPs otherwise you could use for VIPs: subnet address like .0, FGT's secondary wan interface IP, and broadcase IP like .7 if /29.
If option 1, basically nothing additionally you have to do. You just need to give them the current FGT's interface IP in the current /29. Then you can keep confguring VIPs with any of new 8 IPs (if /29).
Toshi
Hi,
To be honest, I always prefer to have the new subnet routed through an existing link, so that I can decided how to use it and where.
If I don't need public IPs directly configured on devices in LAN and only required to do SNAT/DNAT with it, it's a lot more flexible for me to use it for different scenarios.
If they want to do secondary on their device that means that you would also have to configure it as a secondary on your FGT ( i am not a fan of secondary ip spaces ) and would not be able to configure/assign IPs from that space to any device directly and you would also 'lose' 1 IP for usage since it's connected/configured on PE and CPE ( FGT ) .
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.