- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Connection Test
Hello everyone,
I am wondering if FortiGate can have a point-to-point connection with a Cisco router using /31 subnet. And if it does, what is the protocol to enable it? Or is it the usual configuration(default gateway, etc.).
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In general yes, but IMHO you need a /30 mask. Connection will be plain routed, VLAN, IPsec VPN,...whatever you need.
As the FGT drops traffic from unknown sources you may have to make external networks "known" by installing static routes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We use /31 on FGTs at many places like internal interconnections per customer to save IPv4 public IPs. There were some minor bugs related to /31 subnets in the past but those were with 5.2.x. They fixed them. We migrated most of our FGTs to 5.4 by now and planning to go up to 5.6.6 soon. So far I'm not aware of any issues.
