I see now that there is a limitation of 32 secondary IPs per interface on the 90d, this seems very low.
Im on the process of using a 90D (straight routing, no NAT) as an intermediary router to a Linux based management router we have. Long story short this management router has 190 some IPs on its internal interface ranging from /30 to /24 in size that act as gateways for various networks. I cant split the gateways between different interfaces connected to a switch because we use DHCP relay and doing so would cause it to fail.
I have an Imagestream Router sitting next to me I can move this to, but would prefer the Fortigate for its visibility. (this is just routing between two interfaces, no sec profiles, not control, policy is allow all, no NAT)
Is there a way around this arbitrary limit of 32 IPs?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Yes, 802.1q tagging.
Secondary imho & experiences don't scale very will, provides very little protections between secondaries-2-secondaries or secondary-2-primary.
Keep in mind, with 802.1q you will have max value limits also per-chassis
Ken
PCNSE
NSE
StrongSwan
that will break the DHCP relay
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.