i have a verizon internet gateway that i want to use for my redundant internet for my SD WAN. it has two LAN ports.WAN1 already has cable internet from comcast, I want to connect the verizon internet gateway to my WAN2 of my fortigate, which port from the verizon internet Gateway do I use and do i need to configure any passthough settings on the verizon internet gateway?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
We can imagine some solutions as the behavior of verizon gateway is not known:
With bridge mode, the fortigate will get the public IP from the ISP.
With router mode, the fortigate will get a private IP from the router. In that case double NAT will be involved.
The definitive answer will depend on the verizon CE capacity.
Regards, WD
When you want to use your Verizon internet gateway as a redundant internet for your SD-WAN on FortiGate, here's what you need to consider:
LAN Ports on Verizon Internet Gateway: Typically, the LAN ports on an ISP-provided gateway device are there to distribute the internet connection to devices within your network. Most ISP gateways will have one WAN port that connects to the internet, and multiple LAN ports for local devices. If your Verizon Internet Gateway has two LAN ports, either port should work to connect to your FortiGate, as long as the gateway is correctly set up and distributing internet to those ports.
Bridge or Passthrough Mode: To avoid double NAT (Network Address Translation) and other potential networking issues, you'd ideally want your Verizon Internet Gateway to be in a bridge or passthrough mode. This essentially turns the gateway into a simple modem, allowing your FortiGate to handle all routing and NAT functions:
Configuring FortiGate WAN2:
Testing: After configuring, ensure that you test the redundancy. Disconnect the WAN1 (Comcast connection) and see if the FortiGate successfully fails over to WAN2 (Verizon connection).
Important Note: Not all ISP-provided devices support bridge or passthrough mode. If the Verizon Internet Gateway doesn't support it and you're locked into using it, you'll be dealing with a double NAT scenario. While double NAT can work, it can also lead to certain challenges especially with services that require port forwarding, VPNs, or other more advanced configurations.
Thank you soo much for the detailed instructions. ill try it tonight.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1717 | |
1093 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.