Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TJ1
New Contributor

Connect a second Fortigate through a port on the first

We have a need to create a separate connection via one internet ISP, however we must have the first Fortigate 90F supply the connection to the other Fortigate (60D) or it would require significate extra monthly cost.

 

What is the best way to do this?

 

We have extra external IP addresses, so my thought was to do a VIP mapped to an unused external IP address for that 60D and connect it to an unused port on the 90F. The tricky part is do have the external IP address respond to the 60D.

 

Suggestions?

5 REPLIES 5
akristof
Staff
Staff

Hello,

 

Thank you for your question. If you have multiple public IPs, then yes reserve one unused for 60D and create VIP (but this is only if you want to access 60D from internet). Then, create point to point link between 60D and 90F. For example:

60D - 172.16.10.1/30 < link > 172.16.10.2/30 - 90F

And the VIP map to forward traffic to 172.16.10.1. And then you will just need default route on 60D pointing to 90F, you will need routes on 90F to return traffic and maybe ippool to SNAT all traffic to same external IP (if you want to have different public IPs for each device).

Adrian
TJ1
New Contributor

First, thank you for you reply.

 

I incorrectly stated the model numbers which probably won't matter, but it is a 60F (used to be a 90D) that is our primary firewall and it is a 60D that we are attempting to connect through it.

 

I am not sure that I was very good at my initial explaination...

 

The goal is to allow the 60D to function as though it was connected directly to an ISP and retain all firewall functions. I was thinking that I would connect the WAN port of the 60D to a unused port on the 60F, then create a VIP to allow that port to use one of our unused ISP provided external IP addresses. 

 

Is this possible and will it work?

akristof

Hi,

 

Thanks for feedback. Models does not really make any difference in what you are trying to achieve.

My original post still should apply in your scenario and you can use VIP to forward traffic to 60D - this if you will want to access 60D from internet. For traffic from 60D to 60F, you will need to enable NAT. Now it is up to you if you will create ippool with unused public IP or you will just use IP address of external interface to NAT the traffic. As I said, important is to make p2p link between devices, configure correct routing and then enable SNAT/DNAT based on your requirements.

Adrian
TJ1
New Contributor

Do you have a link to any example configurations of what will be needed for the p2p link.

akristof

Hi,

 

It should normal link, you will connect them with cable and configure some IPs from same subnet on each interface. Just imagine that you are doing from 60F ISP router and 60D is connected to the ISP. Same principle.

Adrian
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors