Hi Guys,
So I am not a FGT guru at all.
I run a FGGT60 using 7.2.11 b1740
Here is the scenario, isp has assigned me an IP range up until now I have just been using one. Now I need to use a second and route that IP to a server on port 5. Need that server to have full internet access but not be able to see anything else on the network.
Here is what I have done:
Created new hardware switch with only member port 5 - 192.168.15.1
Server is on that port/switch is getting correct IP info 192.168.15.2 and has access to the internet
Now How do I route my second IP address to that port/switch?
Is this a simple routing issue or do I have to add a secondary IP address on the WAN1 port?
Sorry for what is probably a simple question but I can't seem to find a definitive cookbook article for this and since I am operating remotely I can't really just cowboy it..
thx John
Hi @janssen ,
1) You need to make sure that your ISP knows to route your second public IP via your current WAN1 public IP;
2) Then you can configure VIP for Internet traffic to access the server behind port5.
Check this article for how to configure a VIP on FGT:
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.