help me guys im new with fortinet my question is i have existing router MIKROTIK i have 16 subnet all connected in one interface but planning all to transfer in fortinet 200e the same configuration because some of my switch is not manage switch. how to config one interfaces with 16 subnet thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You do secondaries . I believe you can do up to 16 secondaries per interface
PCNSE
NSE
StrongSwan
The max value doc for 6.0 says up to even 32/interface.
thanks for your reply but. what i need is i can configure in one interface the vlan. more that 16 subnet but my question is not working in ordinary switch.
my existing connection in one interfaces only all the 16 subnet are connected in one interfaces. i want to make the same in FGT so how.
You need to explain your cfg secondarys are easier and vlans are easy we are not sure what your doing
e.g secondary
config system interface edit "dmz" set vdom "root" set ip 10.10.10.1 255.255.255.0 set allowaccess ping https http fgfm capwap set type physical set role dmz set snmp-index 5 set secondary-IP enable config secondaryip edit 1 set ip 10.200.1.1 255.255.255.0 next edit 2 set ip 10.200.2.1 255.255.255.0 next edit 3 set ip 10.200.3.1 255.255.255.0 next edit 4 set ip 10.200.4.1 255.255.255.0 next edit 5 set ip 10.200.5.1 255.255.255.0 next edit 6 set ip 10.200.6.1 255.255.255.0 next edit 7 set ip 10.200.7.1 255.255.255.0 next edit 8 set ip 10.200.8.1 255.255.255.0 next edit 9 set ip 10.200.9.1 255.255.255.0 next edit 10 set ip 10.200.10.1 255.255.255.0 next edit 11 set ip 10.200.11.1 255.255.255.0 next edit 12 set ip 10.200.12.1 255.255.255.0 next edit 13 set ip 10.200.13.1 255.255.255.0 next edit 14 set ip 10.200.14.1 255.255.255.0 next edit 15 set ip 10.200.15.1 255.255.255.0 next edit 16 set ip 10.200.16.1 255.255.255.0 next edit 17 set ip 10.200.17.1 255.255.255.0 next end nextend Ken
PCNSE
NSE
StrongSwan
sir why do i need DMZ.? only i need to config internal connection between the 17 different ip address. i want all this can connect each other.
thanks
Sir, Please check the image. i need all of my ip range connect in any port so how/?
You can change the firewall from switch to interface mode:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD40353
Then you can use secondary IPs (subnet) on the Interface as suggested previously or you can a create VLAN interface for each subnet.
thanks for the reply here is my picture of my network that i want thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1091 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.