I have network provider who provided internet via fiber with SFP module - i putted this module and everything works but the subnet is /29 so i have x.x.x.1 provider gateway, x.x.x.2 fortigate. But i have other devices that i would like to address with this public space - x.x.x.3 and x.x.x.4, it is possible to make switch with wan/sftp and for example with ports 7,8 where i can connect devices with ip's x.x.x.3/4 and default gateway .1? - fortgate will be transparent for them.
Device: FG 80F.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
why does one want devices to be directly reachable from wan side?
The most elegant soulution probably is to set up secondary ips on your fibre wan and then create VIP to forward what you need to the devices.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Basically you can, but as explained by @sw2090 it is much better and more secure to put your equipment behind your firewall and make them accessible via VIP.
https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/510402/static-virtual-ips
I'd recommend that at least for static services. It however causes problems with services that use some dynamic like e.g. active FTP. or FTPS I couldn't get FTPS to run with VIPs...
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
I know that "better" would be putting devices behind but this is out of scope ot this discussion. Decision was made - as internet link is "shared" between few persons everyone want to have their public ip and this cannot be changed.
If this is possible, can someone advice me how to do this?
I don't want to buy another device switch with sfp and connect devices here...
Yes this should be doable by grouping few FGT interfaces in a HW/SW switch and it should be transparent for FGT when they communicate with each other.
I can group wan interfaces with other? This is only logical difference and i can you all of them in any scenario?
Yes, I can do that on my FOS 6.2.x.
so that means they all want to expose themselves to the internet... m(
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
They will have their own firewalls.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.