Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nobody58
Visitor

Forti vm strange request

Hello,

I installed fortivm on an esx in the datacenter.

Maybe it may sound a little strange, but the following configuration is requested.

Datacenter gave me an external ip for example; 10.20.30.40/29 subnet.
As a gateway, I was informed that it was 10.20.30.43.

Step - 1 ) I will define the ip addresses 10.20.30.41 and 42 as wan ports on the port2 interface in the firewall. Servers in the local network will be able to access the internet via this wan port. Port1 is set as internal (Lan) and port2 as wan port and I can access the internet by giving static route (gw 10.20.30.43) and writing lan to wan rule.
There is no problem in this part.

Stage - 2 ) 1 db and 1 web service (iis) server 2019 machines that I have installed (iis) server 2019 machines without giving ip address from local network, giving 10.30.40.44 and 10.30.40.45 addresses statically from direct wan ip block and I am expected to pass the traffic on these machines through the firewall. If I write 10.30.40.43 as gw to the machines, the firewall is not activated. Somehow I need to direct this traffic to the firewall. The request seems a bit absurd, but this is how it is requested. Is it possible to do this? What kind of configuration should I do?

1 REPLY 1
AEK
SuperUser
SuperUser

Hi

You can do as follows:

  1. Put FGT/port1 and the two VMS (DB & IIS) on the same vSwitch
  2. Configure them all three in the same subnet
  3. Set the default gateway of the 2 VMs to the FGT/port1 IP address
AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors