We currently have a cisco FTD1140 as the main firewall but are now planning to add a Fortigate 100F in front, between the ISP and Cisco. Not exactly sure how to configure the IP's of the Fortigate 100F to allow traffic to passthrough. The Fortigate will serve as a filter in order to reduce the load on the Cisco. Any ideas on how to configure the Fortigate.
Eventually we will setup the fortigate as SD-WAN. Here's a picture of what I believe it will look like.
One option would be to put the firewall inline using virtual wire pair, it will inspect the traffic as it passes through but does not do any routing, etc.
The second, would be to put the public ips on the firewall and then create a /30 or similar network between the fortigate and cisco to route the traffic through. All VIPS, IP Pools, VPNs etc would probably want to be moved to the fortigate in this scenerio.
User | Count |
---|---|
2625 | |
1395 | |
810 | |
671 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.