Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jan_Scholten
Contributor

Comparison Transparent/Route mode

I am looking for a comparison of transparent and route/nat mode. What are the benefits for transparent, what are the drawbacks? Tranbsparent: + easy to implement (no need to change IPs) + supports antivirus, IPS, ... - VPN only to management IP - no dynamic routing (obviviously) NAT/Route mode: + supports antivirus, IPS, ... + acts as gateway, possible to implement redundat routes/interfaces + VPN in interface and or Policy mode + dynamic and policy routing - may need to change IPs, create new IP networks .. .. Is there any other feature transparent FG can' t provide? What do you choose if you can?
7 REPLIES 7
FortiRack_Eric
New Contributor III

In my opinion you should approach this in another way. Use NAT/Route mode unless you really need transparent mode. Cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Jan_Scholten
Contributor

I need some arguments for a a customer who has a transparent fg whether or whether not to switch to nat mode.
claumakurumure

In this case you need to compare the features on the current firewall and the fortigate. Because the reason why they have it in transparent mode maybe because the curent firewall does not support the following. - Webcontent filtering - IPS - Application Control - FSAE - etc So you need to find info on the current firewall in fron of the Fortigate. thanks
hezvo uko
hezvo uko
Jan_Scholten
Contributor

The current firewall is a fortigate and i would like to switch that fortigate to a nat/route modus, just because I " fell better" and i prefer nat/route over transparent. So i just thought there maybe some points i could use to support nat/route
claumakurumure

Hi there, You need to find more info here, there could be an ADSL router in front of the Fortigate or something. In transparent mode the fortigate will not be able to sepeare the Trusted network (LAN) from the Untrusted (intenet) at all. can you give us the sket network diagram maybe there is something that I am missing here. Thank you
hezvo uko
hezvo uko
Jan_Scholten
Contributor

The Fortigate is behind a SDSL and another 3rd PartyFirewall. This should not be changed. So the fortigate is just sitting in thet data stream behind the checkpoint for doing A/V IPS a.s.o. The Fortigtae has a couple of transparent vdoms for placing it in different networks " in front of public server" , " between clients and there gateway" ... It will porbably never do vpn, but may do proxy for http(s) somewhere in the future.
emnoc
Esteemed Contributor III

Another drawback with transparent mode, you don' t the option tio do SSL inspection or webproxy which I guess falls under webcontent. Also VPN terminations for the obvious reasons. What are you try todo or gain ? would be my 1st question. I would not place try todo a 1 for 1 match comparison, since each method is used differently to achieve a certain function or purpose.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors