Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HT_JDC
New Contributor II

DMZ configuration of Fortigate 60E does work at Fortigate 90G.

Hello Experts,

 

We have aaa.bbb.209.136/28 global IP address range by provider. The connection is PPPoE.

As wan1 IP address, aaa.bbb.209.142 is set at unnumbered IP. At DMZ, aaa.bbb.209.137/28 is set.

Everything works at Fortigate 60E. Recently, we bought Fortigate 90G to replace it with.

However, the same IP addresses cannot be configured at Fortigate 90G.

When we try to set aaa.bbb.209.137/28 for DMZ, an error message such as

"overlapped network with wan1" is shown. How can we solve this situation?

For information, aaa.bbb.209.142 can be configured at 90G.

 

Thanks in advance and best regards,

 

1 Solution
Yurisk
SuperUser
SuperUser

Without trying to understand the context - the setting to disable overlapping networks check is 

set allow-subnet-overlap

Under config sys settings

To read more https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-subnet-overlap-to-set-IP-addresses-... 

 

https://yurisk.info

View solution in original post

https://yurisk.info
3 REPLIES 3
kaman
Staff
Staff

Hi HT_JDC,

In FortiOS (especially in newer models like the 90G), if two interfaces have IPs within the same subnet, the system flags it as overlapping and prevents configuration—unless special routing techniques are applied.

Your WAN1 interface is using an IP (.142) within the same subnet as your DMZ (.137/28), which the FortiGate 90G now treats as conflicting.

As a solution, you can usea  Secondary IP Address on DMZ
Instead of setting .137/28 directly on the DMZ interface, use a /32 host IP as a secondary IP.

If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,

Yurisk
SuperUser
SuperUser

Without trying to understand the context - the setting to disable overlapping networks check is 

set allow-subnet-overlap

Under config sys settings

To read more https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-subnet-overlap-to-set-IP-addresses-... 

 

https://yurisk.info
https://yurisk.info
HT_JDC
New Contributor II

Hello,

 

>set allow-subnet-overlap

 

Works. Thanks a lot.

 

Best regards,

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors