Hello everyone,
I am wondering if FortiGate can have a point-to-point connection with a Cisco router using /31 subnet. And if it does, what is the protocol to enable it? Or is it the usual configuration(default gateway, etc.).
Thank you.
In general yes, but IMHO you need a /30 mask. Connection will be plain routed, VLAN, IPsec VPN,...whatever you need.
As the FGT drops traffic from unknown sources you may have to make external networks "known" by installing static routes.
We use /31 on FGTs at many places like internal interconnections per customer to save IPv4 public IPs. There were some minor bugs related to /31 subnets in the past but those were with 5.2.x. They fixed them. We migrated most of our FGTs to 5.4 by now and planning to go up to 5.6.6 soon. So far I'm not aware of any issues.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.