Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Schime85
New Contributor

Static public IP / 2nd subnet from ISP / great if I can pass IP pool to another router

Hi guys!

 

Like in the subject we have a Forti 40f with a static public ip over dhcp client from ISP.

From the ISP we also get another public IP block/pool which is routed to our fixed IP. The goal would be that I can use my new public IP's on my 2nd Mikrotik router. Many posts about this say that VIP's should be used but as I'm not a Forti native guy can I find some GUI tutorial for that?

 

Thanks!

1 Solution
Toshi_Esumi
SuperUser
SuperUser

I think many other posts mentioning how to route public subnets through an FGT. You just need to configure it like a router in old days.


If you just want to pass whatever the subnet mask, say /29, to Mikrotik so that the Mikrotik can do DNAT/VIP by itself, the interface subnet between the 40F and Mikrotik can be private one.
Or, the Mikrotik just need to have the public IP in the subnet on its wan interface, you can assign the /29 on the interface between them.

In either case, the key on the FGT is to have a pair of no-NAT policies for both inbound and outbound directions. If the formar, you also need to have a static route for the /29 toward Mikrotik.

 

Toshi

View solution in original post

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

I think many other posts mentioning how to route public subnets through an FGT. You just need to configure it like a router in old days.


If you just want to pass whatever the subnet mask, say /29, to Mikrotik so that the Mikrotik can do DNAT/VIP by itself, the interface subnet between the 40F and Mikrotik can be private one.
Or, the Mikrotik just need to have the public IP in the subnet on its wan interface, you can assign the /29 on the interface between them.

In either case, the key on the FGT is to have a pair of no-NAT policies for both inbound and outbound directions. If the formar, you also need to have a static route for the /29 toward Mikrotik.

 

Toshi

Schime85

That would be a possible solution, thank you for that.

After all we get a own interface with it's own ip subnet where we can install the 2nd router. So they are working independent from each other and everybode is happy :)

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors