We need to get two VMs to bypass the Fortigate and just go straight out to the internet.
How do we do that?
Hi, @alkemyst
When you mention bypass FortiGate, it will depend on how your enviroment setup be
What kind of VM is that
How will you let VM obtain Internet without FortiGate, assuming you should have another router there has public facing
FortiGate in general, does not control how your source traffic will flow hence if you would like VMs to go out to Internet without FortiGate invovled, properly consider how give VM different routing or path using different network in your setup
So I am new to this org. We are using VSphere and everything has to go out the Fortigate because some internet only traffic also is tunneled (which I am not used too). The recommendation is create a new vSwitch with it's own VLAN (I am used to just adding another VLAN to a vSwitch) and then assign it to a port on the Fortigate. I still need to figure it out.
You can absolutely do this, but those VMs need a path that doesn’t traverse the FortiGate at all. The simplest method is to create a dedicated VLAN/vSwitch in vSphere that uplinks to a router or switch offering direct internet access, instead of an interface on the FortiGate. Once that path exists, the VMs will just follow the default gateway of that new network and bypass the firewall entirely.
| User | Count |
|---|---|
| 2787 | |
| 1423 | |
| 812 | |
| 746 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.