Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NETWORK_USER
New Contributor

Integrating Fortigate into existing network

Hello, We have a Fortigate 300 C which is not in the default path to the internet. It is connected to the network gateway router and the gateway router policy routes all the traffic going out to the internet to this FG300C. We want to move this firewall behind the gateway router and implement FG HA. We also plan on moving all the IPsec tunnels and NAT from the gateway router to this firewall. I would like some input on what would be the best way to move the firewall behind the gateway with minimal downtime. One way I am thinking of doing it is by connecting the second FG300C(which is right now on the bench as a backup) behind the router and configuring it to allow all traffic through(open policy) to the gateway router. Once I have done this I can move the configurations (ipsec vpns, nat etc) from the gateway router to this firewall behind the router and once I have moved all the configuration that i want to move, I can restrict the policy as required and apply web filtering and remove the other firewall and connect it to this firewall to make HA pair. Do you think this is better then configuring the firewall offline? Thank you.
5 REPLIES 5
rwpatterson
Valued Contributor III

If you have more than one public IP address, I would set the FGT up on a second, and use it that way. You can then roll everyone over at your leisure.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
billp
Contributor

+1 on Bob' s advice. I have upgraded my Fortigate several times, and I always like to set it up and test it live before replacing an existing/working box. Before cutting over, I run through a written checklist and verify various combinations of settings, logins, filters, etc.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
emnoc
Esteemed Contributor III

Even better yet, do you even need the network router? Based on what you stated, I see no need for router+firewall. Could be one less device and/or you can even reposition the router to do something else imho.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
SuperUser
SuperUser

Placing a Fortigate as VPN gateway behind a router (i.e. into a transition network) is troublesome. A VPN gateway needs a public IP address, right? just my 2 ct.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
rwpatterson
Valued Contributor III

ORIGINAL: ede_pfau Placing a Fortigate as VPN gateway behind a router (i.e. into a transition network) is troublesome. A VPN gateway needs a public IP address, right? just my 2 ct.
Or a pass through from the gateway device.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors