Hello,
I am working on coming up with a design to migrate from an older ASA to a 100F. The current config is 2 ISPs coming in to an Edge Router where it is advertising a full class C public network block through BGP. The ASA is handling a lot of NAT policies for all the public services living in a DMZ zone.
I will have 2 100F devices. I was thinking of putting the 1st device (FG1) in parallel with the ASA and giving it an unused public IP on the WAN side and creating the same zones (dmz, lan, voip) with an unused IP in those zones. I would like to move one service at a time from the ASA to the Fortigate. I am also trying not to modify the ASA in any way. Is there a way I could put the second 100F (FG2) in between the ASA and the inside zones and do some type of routing to allow for me to cut a single service over at a time?
Thansk, Matt
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1669 | |
1082 | |
752 | |
446 | |
225 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.