Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
papapuff
New Contributor II

Help - Need advice for configure firewall on some networks

Hi there, Need advice and help please. I manage 3 networks. each network basically not connected each other. currently I have 1 ISP to supply internet for those networks. Internet <-> modem router <-> net_A, net_B, net_C. each network assigned one IP public, and each network has firewall router to manage internet rules for its clients. So may be I can draw for each network like this: modem router <-> firewall PC/Gateway (Linux based on small PC) <-> switch <-> clients Now I want to manage all networks with Fortigate, just my plan now: Internet <-> modem <-> fortigate <-> net_A, net_B, net_C * each network still use its own firewall gateway (if possible). with fortigate, I expect I can build vpn for certain network, and from other site can access some servers. Unfortunately, between networks (net_A, net_B, net_C) use same IP segment (each network use segment 10.0.0.x for their internal network). Maybe in here I need virtual IP and transparent mode (just start learning now about that technology). What I need is, can Fortigate do: 1. determine someone connect to only certain network via vpn-ssl. as example user_A only can connect to net_A, can' t connect to other network. this user connect via vpn-ssl 2. determine other site only can connect to certain server on Net_B 3. determine vpn from other site (different location) to connect net_C only. other site will use fortigate too. I will use FG-100D for this job. need advice and help please. thanks.
1 REPLY 1
Istvan_Takacs_FTNT

It is possible if the Linux PC/gateways support IPsec VPN to your 100D. You can then configure SSL VPN access on the 100D for individual users connecting via the Internet and want to have access only to their dedicated network. Overlapping subnets are not an issue, the FortiOS handbook has a few pretty good examples for exactly the same scenario. I' d suggest to start at section " How to work with overlapping subnets" . You can download the guide from http://docs.fortinet.com/d/fortigate-fortios-handbook-the-complete-guide What I would start with is to sort out the IPsec VPN config to the 3 networks to see if it can be done. Not much point to talk about anything else until you have a working connection to those remote sites.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors