Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nsantin
New Contributor III

Double routing on one interface

Hi, I have a new pair of FGT 60-C' s that Im configuring with a new ISP (e10-fibre connection) My question is similar to this post: http://support.fortinet.com/forum/tm.asp?m=79153&p=2&tmode=1&smode=1 in which my ISP has given me a " CE - Customer Edge" IP address to be configured on the router as well as a block of public IPs for my use. This is what I have: ISP Network IP Address: 1.1.1.216 255.255.255.252 ISP Broadcast IP Address: 1.1.1.219 ISP Default Gateway IP Address: 1.1.1.217 (Assigned to the ISP provider edge [PE] router customer facing interface) ISP IP Address: 1.1.1.218 (To be assigned to the customer edge [CE] router ISP facing interface) Customer Network IP Address: 2.2.2.144 255.255.255.240 CustomerBroadcast IP Address: 2.2.2.159 CustomerAssignable IP Addresses: 2.2.2.145 - 2.2.2.158 (To be assigned however you like) Im a little confused on how to setup the WAN interface. How do I setup my WAN interface (with the 2.2.2.x IPs) to use the 1.1.1.217 gateway? From what I see, it looks like I need 2 routers, one to route to the ISP and one for my public block. Can i configure this on the FGT60? Any help appreciated! Thanks
13 REPLIES 13
nsantin
New Contributor III

I did get this working until I introduced my PBX into the mix. I tried to have the FGT act as a router to the PE gateway and I couldn' t get it to work. Then if I tried to have the PBX directly connect to the ISP with the FGT I would have mixed results. So I had to abandon this and put a spare cisco 1841 router I had in front of the FGT and PBX. Everything works like a charm now, except I did lose and IP address on my block as it became the internal gateway on the cisco.
jtfinley

What Ive done in the past was vdom and use transparent together. Perhaps when you get spare time or a window to play with it again...let me know and I' ll share my config.
Roman_Redl
New Contributor

This worked like a charm, just set up one IP-Pool per external IP from the routed net and select external IP´s easly. I was told by the ISP the reason for this setup is to change the DHCP-given IP any time without the need to change the rest of he customer setup (like MX etc.). One thing: how to setup the vpn (site to site as well as dial-up) with this IP-Range ? regards, Roman
Roman_Redl
New Contributor

according to this post http://support.fortinet.com/forum/tm.asp?m=79153&p=2&tmode=1&smode=1 your default route should be se to 2.2.2.144 . in my case this adress is stated as the gateway of the customer net, but of course not pingable, should it be, when used as gateway ? regards, Roman
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors