Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SixtyIsTheNewForti
New Contributor

Running Fortigate along side Cisco FTD

We would like to migrate our datacenter FTD firewalls over to Fortigates. We would like to run these firewalls in parallel and migrate services selectively. Both sets of firewalls are connected to different ISPs. The datacenter core is learning a default route from the FTDs currently. Until the time migration is completed, how can we ensure that the traffic that comes through the Fortigates to the core goes out that same path? Do I need a source NAT on the Fortigates to translate the source addresses for traffic destined to the datacenter core? Or is there a better way here?

5 REPLIES 5
Jean-Philippe_P
Moderator
Moderator

Hello SixtyIsTheNewForti, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello SixtyIsTheNewForti,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Markus_M
Staff
Staff

Hi Sixty,

 

the layout will help here, but you should generally use SNAT of your network outbound. If you have internal traffic you should not need SNAT as I doubt that internal resources will have traffic going over both firewalls simultaneously.

 

Your routing should otherwise automatically deal with the respective traffic going over the old firewall. Change the distances/metrics of your routing protocols in order to switch to the new firewalls.

 

Best regards,

 

Markus

SixtyIsTheNewForti

Hey Markus, thanks for your reply.  Imagine 2 ISP clouds at the top and 2 sets of firewalls (FTD and Fortigate) connected to each of those ISPs using a unique public address space. Imagine core datacenter network behind these firewalls. When we migrate a web server from ISP1 over to ISP2 and have it come through the Fortigates, how will my datacenter core override the default route that is pointing to go out the FTD? Hence, the reason, I am asking if we can SNAT the traffic that comes in via the Fortigates using probably its LAN interface pointed to the core? Hope it makes sense.

akristof
Staff
Staff

Hello,

There is no universal answer for this. Probably the most often scenario is that FortiGate is preconfigured with Vlans, IPs, routing, etc, all cables are connected but interfaces are disabled. And then when the migration happens, old firewall is disabled/shutdown and FortiGate interfaces are enabled. And then it is up to network to see if routing is up, traffic flowing, etc.

Adrian
Labels
Top Kudoed Authors