Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
get_right
New Contributor

Add new WAN link with static IP address

Dear All,

 

First off, thank you for taking time to read this thread.

 

I am trying to set up a new WAN link (with a public static IP address on WAN1) that connects to an ISP managed router along side an existing PPPoE connection (WAN2, functioning for common user traffic).

 

The new connection has a static IP assignment on the internal side on the router (public address, internet routable) that can be pinged remotely. Upon setting an IP address on the WAN1 interface of the Fortigate 100D unit, I am unable to ping the WAN1 interface remotely.

 

What I have tried so far:

 

[ul]
  • Over-rode the implicit deny all in IPv4 Policies with ACCEPT all from any interface - did not work.
  • Set up policy routing to route outgoing connections to particular addresses to use WAN1 - did not work.
  • Re-checked the ISP managed router to see if there is a discrepancy with the addressing - works fine when I configure the static IP directly on the laptop.
  • Set up a packet capture on the WAN1 interface. The capture shows incoming packets, but Wireshark also notes that there wasn't a response sent to the ICMP request.[/ul]

    Attached is a picture of what I am trying to achieve. Essentially, I need everybody to have the same internet access (WAN2, using PPPoE), and use WAN1 only for specific internet addresses.

     

    I also read online about configuring VDOMS, but I am unsure whether I might need such a config. for this simple a set up.

  • 5 REPLIES 5
    GusTech
    Contributor II

    get_right wrote:

     

    Attached is a picture of what I am trying to achieve. Essentially, I need everybody to have the same internet access (WAN2, using PPPoE), and use WAN1 only for specific internet addresses.

     

    If this is the only goal you can use policy routes

    Fortigate <3

    Fortigate <3
    get_right

    Hi BrUz,

     

    That is the ultimate intention, yes. However, for starters, I am unable to ping the static IP assigned to the WAN1 interface remotely.

    Fullmoon

    hi get_right, see to it both wan links have the same distance. could you validate both gateways are available in routing monitor?

    agree with bruz, through Policy Based Route or PBR you can achieve what you're aiming for.

    Fortigate Newbie

    Fortigate Newbie
    get_right

    Hi Fullmoon,

     

    Thanks for the reply. Attached is a screenshot of my routing table. Setting the administrative distance to the same as that of the PPP connection breaks the internet. My apologies for not having mentioned that before.

    mec313
    New Contributor II

    Not sure if you ever found your answer or not. This may be a simple/stupid question, but do you have ping enabled on the interface? From the comments it didn't seem like you got past that step.
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors