Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
atnsi
New Contributor

Configuration Options for Integrating Camera System Router with Client's Firewall

I’m working on a project where a client is installing a new camera system. The vendor will provide their own router and PoE switch. We need to connect this router to the client’s existing firewall (91G), and the client has available public IP addresses.

 

Can I configure the 91G firewall to pass-through mode, allowing the vendor’s router to use a public IP directly? Or is there a better approach to integrate the vendor’s router with the client’s firewall?

 

BTW, the camera vendor will handle all system management independently and requires full access to their equipment, which will be completely separate from the client’s network.

 

Thanks!

1 Solution
AEK

Yes I'd do it that way.

AEK

View solution in original post

AEK
5 REPLIES 5
adambomb1219
SuperUser
SuperUser

What is the reason to put the device behind the firewall?  Why not use NAT mode? Does the public IP space exist on the 91G itself?  Or in front of it?

atnsi

The camera vendor wants complete access to their equipment and cameras. Yes the firewall is handling the public IP space.

 

They also want their router to have a public IP address.

AEK
SuperUser
SuperUser

You can use virtual wire pair or transparent VDOM.

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/166804/virtual-wire-pair

But I'd prefer use a VIP instead, I mean the public IP defined on FortiGate and mapped to private IP of the camera router. I find this cleaner and you can do better security.

AEK
AEK
atnsi
New Contributor

would a DMZ with VIP a better solution?

AEK

Yes I'd do it that way.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors