Hi Guys,
So we were using a router with two VLAN 10 and 20, connected to two different APs and everything was working fine.
Today we purchased a firewall and we placed it before the router (refer to the image). I created two static routes 192.168.110.0 with Gateway 192.168.100.2 and 192.168.120.0 with the same Gateway. Still, we are not able to access the internet.
Any idea what I am doing wrong? Any other way to configure this whole setup?
Hello,
Thank you for your question. Setup looks easy, so FortiGate should have 3 routes in the routing. 2 routes for your internal subnets and then default route to reach internet. And then you need to have correct firewall policy to allow traffic from your internal interface to your external interface with NAT enabled. You can check this guide to do some debugs to see if something is blocking it:
To add, the old router needs an additional default route to 192.168.100.1. All of your hosts, including the APs, can then have either 192.168.100.2 (old setting) or .1 (correct setting) as their gateway. NAT on the old router should be removed.
If you get the routing correct (ping from router/firewall, this is not using policies), then you need policies on the FGT to allow the traffic.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.