Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

Fortigate 200F mgmt port config

Hi

I put mgmt port in           vlan10(192.168.10.10/24) and i wrote a static route like this: 192.168.10.0/24  192.168.10.1 mgmt. But i can not access the FGT webui at all. What should i do to be able to access webui from mgmt port?

Reza F.
Reza F.
8 REPLIES 8
funkylicious
SuperUser
SuperUser

Hi,

You put a route towards your own configured subnet on the FGT, therefore that might be the issue.

"jack of all trades, master of none"
"jack of all trades, master of none"
rezafathi

Hi funkylicious,

 

All interface vlans are on fortigate except vlan 10 which is on cisco 3750 switch. So what correct route do i have to write?

Reza F.
Reza F.
funkylicious

Based on what you are saying is that you have, let's say by example, the ones from below.

intf VLAN A - 192.168.A.1/24
intf VLAN B  - 192.168.B.1/24
intf VLAN C - 192.168.C.1/24

intf VLAN10 - 192.168.10.10 /24

 

You are trying to access from subnet VLAN A the interface which is VLAN10, therefore you already have a route back to VLAN A directly connected to interface VLAN A so it know how the return traffic to exit the correct interface.

If this is a setup that you are using, you can delete the static route ( you would need a firewall policy with towards VLAN10 from the source interface where you are initiating the traffic.

But if the source IP from which you are trying to access VLAN10 interface is not defined locally on FGT, then yes, you need a static route with destination subnet X - 192.168.X.0/24 to mgmt interface and 192.168.10.10 nexthop if that ( the switch ) is the default gateway for inbound/outbound traffic .

"jack of all trades, master of none"
"jack of all trades, master of none"
rezafathi

The valn which i am going to access vlan 10 is vlan 30. Vlan 30 is a sub interface (port1) on fgt but vlan 10 is not on fgt and it's int vlan is on cisco switch. If i want to use policy the source interface would be vlan30 but how about outgoing interface?

Reza F.
Reza F.
funkylicious

Then you would only need to create a firewall rule from vlan 30 to mgmt.

But you can also activate http/https under vlan30 and access the GUI with the IP of the interface, without any rule required.

 

"jack of all trades, master of none"
"jack of all trades, master of none"
rezafathi

Because mgmt port is set to dedicated management , is not shown on interface list when you create a policy

Reza F.
Reza F.
funkylicious

That might explain your situation at the moment.

I personally dont use the mgmt interface to be dedicated for management.

I would rather do that with any regular interface, like in your case it can be the on vlan30, you would need to activate the services on it.

"jack of all trades, master of none"
"jack of all trades, master of none"
rezafathi

I wanted to seperate mgmt traffic from other traffics.

Reza F.
Reza F.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors