Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AnotherFortiUser
New Contributor II

Disable Bypass Mode on Power-Off on FortiGate Rugged60F

Hi,


in the documentation of the FortiGate Rugged60F it says, that port internal4 and wan1 form a bypass pair.
As I understand by reading documentation (https://docs.fortinet.com/document/fortigate/7.4.7/hardware-acceleration/754739) this results in forming a hardwired connectivity between these ports in the case of a power failure / power-off.

This might result in a security issue, if using those two interfaces in different network segements / vlans, if I understand this description correctly.

I also couldnt find any documentation on how to disable this feature - only for different FortiGate models. And those either say its possible to disable via CLI (80/81), but a different model describes it cant be disabled and is the default configuration (Rugged 90D):
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-poweroff-bypass-and-bypass-watch...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Bypass-Ports-on-FortiGate-Rugged-90D/ta-p/...


Could you help me answer the following questions:
1) Did I understand the documentation correctly and is my conclusion correct, that you shouldnt use those two ports simultaneously in different network zones?
2) If 1 is the case, can this functionality be disabled? Or is the solution, that you just dont use those two ports simultaneously?

Thank you in advance!

Best regards

1 REPLY 1
ozkanaltas
Valued Contributor III

Hello @AnotherFortiUser ,

 

If you use the same VLAN ID or the same network on both wan1 and internal4 interfaces, yes, you are right. They can access each other's network when a power failure. 

 

This feature is especially good if you use transparent mode.

 

Also, in the document, describe how to disable bypass on these ports.

 

image.png

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors