Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
karl
New Contributor

Multiple IPs on PPPOE ("Inbound")

Hello!

 

Using FortiGate 60F

 

I have a client with the PPPoE connection assigning him IP (For Example): 195.10.20.5. The client needs multiple services connected through SSL (443) port, so the ISP assigned him a (routed) segment with a /30 mask on the first IP. 

Now the question is: how to route (NAT) traffic from other IPs through PPPoE IP? 

 

Best regards,

 

Karl

 

 

3 REPLIES 3
sw2090
Honored Contributor

hm /30 means 4 hosts in that segment. 

You get 195.10.20.5/30.

So you segment is from 195.20.4 to .7.

But: .4 is Network address and .7 is broadcast address.

.5 is your FGT Wan IP

so I consider .6 is the gateway ip

if so there is no ip left over to use in that segment...

 

If there were you could add it as secondary ip on that wan and then use it as source/destination ip in policies if needed.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
karl
New Contributor

Hi! 

 

Thanks for the response.

I was not clear enough. My WAN IP is 195.10.20.5/32 (one IP). The additional IPs are 212.10.20.220/30 (for example)... Totally different IP space.

Problem was that ISP did have the 195.10.20.5/30 available...

 

I tried with a secondary IP, with no success. However I managed to "quick fix" the problem with VIP and NAT (I'm using VIP to NAT 212.10.20.220 ==> 195.10.20.5, and 212.10.20.221 ==> 195.10.20.5), but I'm afraid the solution isn't optimal.

Why not? I have to "allow" traffic from one 212.10.20.220 ==> 195.10.20.5, port 443 through the firewall and every other dropped packet (different sniffers, port scans and **bleep**) is market as "security issue" in FortiAnalyzer. 

The "final" option would be to place a router before the firewall but, than again FG should handle this with ease... I just can't figure out how... 

Toshi_Esumi

The ISP is just delivering traffic destined to 212.10.20.220/30 to the interface/pppoe IP 195.10.20.5. So you can use all four 212 IPs for VIP outside IPs (you need to combine it with SNAT + ippools to make it 1:1 NATs), or .221/30 on an internal interface (or VLAN) then .222/30 on the server to just route through.

 

Outgoing routing would just follow a default route with dynamic GW, which pppoe must have installed automatically.

 

Toshi

Labels
Top Kudoed Authors