Hello team,
I need help configuring the Fortigate 40F as a VPN and a Firewall.
Currently, the ISP modem is connected directly to the ISP router. it is also acting as the DHCP server.
The Fortigate has to be behind the router as per the ISP rules. They will configure a DMZ and forward all the traffic to the fortigate. That's what they said.
My worry is, I don't have a public IP. We only get it on the public port on the ISP router and it is Dynamic. How will the fortigate act as the VPN gateway without having an assigned public IP address.
appreciate your help
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You need to look into dynamic dns entry to point to the ip, possibly see if you can run this on the ISP router
Hi James,
Thanks. I already have a DynDNS subscription and it is now configured on the firewall.
You mean, from the router, the connection through that should be also routed to the firewall, correct?
you would have to use some ddns in some way to have a unique FQDN as Gateway. Best way here as said is to do that on the router.
Then you might have to portforward on the router to the FGT to enable VPN Connection attempts to reach the FGT.
I'm not using SSL VPN here but for IPSec I need to portfoward 500/udp (IPSec) and 4500/udp (NAT-T) on my routers to be able to connect a vpn.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
it should work fine for ssl vpn.
you could run into issues with ipsec, depends on the Router settings and possibilities, but should work normally as well.
What probably wouldnt work is the autoconfiguration of ssl vpn over ssl web portal.
The reason to have the dynamic DNS on the router is the firewall will be a little slow to recognise any public IP change, the router should detect it straight away
If your IP address remains static most of the time, you can simply setup a dns pointer and it should be fine. If it changes frequently, you can look into using a dynamic dns service to connect to it. As long as they are forwarding all the traffic, it should be fine.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.