Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lightmoon1992
New Contributor

Fortigate in the middle of dual links

Hi all I’m trying to deploy clustered Fortigate 800 with transport mode in the middle of two 100-based Ethernet links. The point is that each one of those two links belong to different VLAN tag (1st is 100, 2nd is 200) and those two links are coming from a load balancer. The problem is when a request packet initiated over the first link for example, the response may come back over the second interface, which valuate the concept of any stateful firewall, however, I thought if there is any way I can work around this so the Fortigate unit will consider those two links as one and no packets will be dropped?

Mohammad Al-Zard

 

Mohammad Al-Zard
8 REPLIES 8
laf
New Contributor II

What does transport mode suppose to do? What do you think if you will connect those two links to a single port, putting that port in trunk mode ? If possible make a small sketch with your network scenario so we ll ve a better viewpoint.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
lightmoon1992
New Contributor

" What does transport mode suppose to do? " to do mainly IPS in the first place beside AV " What do you think if you will connect those two links to a single port, putting that port in trunk mode ? " I need to eleminate asymmetric routing instance, also so if there is some way we can combine those two lines together, IPS will not see incoming traffic as spoofed one (because of the load balancer) " If possible make a small sketch with your network scenario so we ll ve a better viewpoint." i tried to attach image file, but the dialog keep displaying " the page cannot be displayed" two lines (Vlan 100 & vlan200) comming into Fortigate unit needs to be combined together so it they will be treated as one (something like link aggregation in concept, however, VLAN interfaces cannot be aggregated) Thanks

Mohammad Al-Zard

 

Mohammad Al-Zard
lightmoon1992
New Contributor

not even a word!! please guys i need your help.. anyone need any explanation on this??? Thanks

Mohammad Al-Zard

 

Mohammad Al-Zard
rwpatterson
Valued Contributor III

Have you tried putting both VLANs into a zone? The zone is then a virtual interface that can have rules applied to it like any other.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
lightmoon1992
New Contributor

I will try this and get back with results ASAP

Mohammad Al-Zard

 

Mohammad Al-Zard
rwpatterson
Valued Contributor III

Before you can add these VLANs to a zone, all references to them need to be broken. No ' Firewall Address' entities, no policies, etc. If this is a production unit, that will be tricky. Good luck

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
lightmoon1992
New Contributor

But are you sure that member interfaces will be treated as one logical interface? Would this eliminate asymmetric routing instance? I did some reading about zones, but they only say that it simplify the policy creation and firewall policies. Does that include treating them as one unit in other tearms? Thanks,

Mohammad Al-Zard

 

Mohammad Al-Zard
rwpatterson
Valued Contributor III

Technically, I' m not sure about the asymmetric routing thing, but they are treated as equal when it comes to managing and provisioning. This may be a question for FGT support... I have zoned several interfaces together, and yes, they are as one. (like the Borg!)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors