- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Configuration Options for Integrating Camera System Router with Client's Firewall
I’m working on a project where a client is installing a new camera system. The vendor will provide their own router and PoE switch. We need to connect this router to the client’s existing firewall (91G), and the client has available public IP addresses.
Can I configure the 91G firewall to pass-through mode, allowing the vendor’s router to use a public IP directly? Or is there a better approach to integrate the vendor’s router with the client’s firewall?
BTW, the camera vendor will handle all system management independently and requires full access to their equipment, which will be completely separate from the client’s network.
Thanks!
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the reason to put the device behind the firewall? Why not use NAT mode? Does the public IP space exist on the 91G itself? Or in front of it?
Created on ‎08-27-2024 07:20 AM Edited on ‎08-27-2024 07:30 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The camera vendor wants complete access to their equipment and cameras. Yes the firewall is handling the public IP space.
They also want their router to have a public IP address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can use virtual wire pair or transparent VDOM.
https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/166804/virtual-wire-pair
But I'd prefer use a VIP instead, I mean the public IP defined on FortiGate and mapped to private IP of the camera router. I find this cleaner and you can do better security.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
would a DMZ with VIP a better solution?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes I'd do it that way.
