Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor

Management port ip

Hi

I have admin interface vlan on my fortigate port 1 and want to assign that ip range to management port too but it says ip conflicts. So how can i set ip address without using defsult gateway?

Reza F.
Reza F.
12 REPLIES 12
dbu
Staff
Staff

Hi @rezafathi ,
As per my  understanding you want to configure IP from  same network in two different Fortigate ports.  You want to overlap the subnet between different interfaces
have a look at this article and let me know if it matches your situation : 
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overlapping-subnet-configuration-for-HA-Ma...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-subnet-overlap-to-set-IP-addresses-...

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
rezafathi

Thanks but i do not want to use subnet overlap function. Currently, i created a vlan for mgmt and assigned it to switch. I did set the ip on mgmt and wrote a default gateway with priority 100. That way i can reach the web ui

Reza F.
Reza F.
dbu

Good to hear that you found the workaround for your situation. 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
rezafathi

Thanks. Is that a good method or not? 

Reza F.
Reza F.
mle2802

Hi @rezafathi,
I think you should have different subnet for that management vlan and the mgmt port. What is the main goal for management vlan and mgmt port?

rezafathi

I want to create a separate vlan for FortiGate management only. currently, i am using a dedicated vlan for mgmt and it only works if i use default gateway. is there any way so default gateway for mgmt is not required? 

Reza F.
Reza F.
mle2802

Hi @rezafathi,

Do you mean set the gateway in the client computer setting?

rezafathi

I mean what is the best practice to configure mgmt port and assign ip address? I want to move all interface vlans from cisco switch to FortiGate.

Reza F.
Reza F.
hbac
Staff
Staff

Hi @rezafathi,

 

Why do you want to use the same subnet for 2 different interfaces? It is not necessary and not recommended. You can simply give it a different subnet. 

 

If you want port1 and management port to be in the same subnet, you can put them in a hardware/software switch. https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/100999/hardware-switch

 

Regards, 

Top Kudoed Authors