Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
architrave
New Contributor

FIREWALL on switch type connection (or similar)

Hi all,

 I need to know if it is possible to configure firewall in the scenario attached. My scope it is to connect the router LAN and firewall WAN and LAN on the same sub net as shown below in the screenshot.

 

Let me know which solution of if this is not possible.

Thanks in advance

 

Archi

 

4 REPLIES 4
Nils
Contributor II

Hi,

Thats not possible, you cannot have the sam subnet on two different L3 interfaces.

You can achieve a similay setup if you choose to run the Fortigate in Transparent Mode.

Then you can "bridge" the inside of the router network through the Fortigate and apply a rule-set to this traffic.

But then the Fortigate will not have any Ip-addresses on these interfaces.

Nils
Contributor II

Otherwise you can create another subnet on the inside-side of the fortigate, ex 192.168.10.0/24.

 

 

architrave

Yes, as I understood....

 sorry for the stupid question but sometime is better to ask a question ... just to try all possible ideas!

 

Best Regards

Archi

ede_pfau

If you only change the intermedia subnet to some other address space (e.g. 172.16.172.0/29) then this would be a perfectly regular setup. I suspect you cannot/do not want to change the router's LAN address...

 

If so, then Transparent mode would be your only choice. UTM won't be affected but VPN could be a bit more effort necessary.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors