Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
UnknownUsr
New Contributor

Help with Enabling Communication Between Two Interfaces on FortiGate

Hello everyone,

I'm working on a FortiGate device and need assistance with enabling communication between two interfaces on the same firewall. Here’s the network setup:

  • Interface 1: Connected to the 192.168.1.0/24 network.
  • Interface 2: Connected to the 172.16.0.0/24 network.
  • Interface 2 also has an Access Point from Unifi connected to it, and I need this AP to communicate with the 192.168.1.0/24 network for remote management.

I have already:

  1. Created firewall policies to allow traffic between the two networks. Both inbound and outbound rules are set to allow the communication.
  2. Set up static routes for both networks to ensure the traffic is routed correctly between the two interfaces:
    • For the 192.168.1.0/24 network, I configured a route with gateway 192.168.1.1 and the interface set to Interface 2 (the one connected to the 172.16.0.0/24 network).
    • For the 172.16.0.0/24 network, I configured the inverse: gateway 172.16.0.1 and the interface set to Interface 1.
    • I also tested other variations, including a route without a gateway, but none of them worked.

Despite the above configurations, the devices on each network are unable to communicate with each other. I’ve verified the firewall rules, and everything is set to allow, except for NAT, which is disabled. All the services and access permissions are set to all for both sides.

The specific challenge I’m facing is with the Unifi Access Point. I need the AP to be able to communicate with the 192.168.1.0/24 network for remote management, but so far it hasn’t been successful.

Could anyone provide guidance on what might be missing in my setup or suggest any additional settings or troubleshooting steps I should follow to enable communication between the two interfaces, and allow the AP to connect to the 192.168.1.0/24 network?

I would really appreciate your help!

Thank you in advance!

1 REPLY 1
dingjerry_FTNT

Hi @UnknownUsr ,

 

There is something wrong with your static routes settings:

 

  • For the 192.168.1.0/24 network, I configured a route with gateway 192.168.1.1 and the interface set to Interface 1, not Interface 2.
  • For the 172.16.0.0/24 network, I configured the inverse: gateway 172.16.0.1 and the interface set to Interface 2, not Interface 1.
Regards,

Jerry
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors