Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Yac
New Contributor

Static route between 2 fortigates does not work correctly.

Hi,

If I summarize correctly, we have 2 sites A and B.

On site A, we have the fortigate which is a NAT router and the ISP's internet connection is connected to the fortigate.
On site A, we have the fortigate which is a NAT router and the ISP's Internet connection is connected to the fortigate's WAN port.
On site B, we have a 2nd Fortigate, and have connected port 1 of Fortigate1 to the WAN1 of the second Fortigate.
On the Lan of the second Fortigate, we've allocated the CCTV cameras, and we'd like to view them from our site A.

Fortigate1 LAN IP address: 172.20.100.1/24

Fortigate 2 LAN IP address: 192.168.1.1/24

Fortigate1 WAN IP address: 10.1.10.1

Fortigate2 WAN IP address: 10.1.10.2

Yacer ALI
Yacer ALI
16 REPLIES 16
Toshi_Esumi
SuperUser
SuperUser

FortiGate2's WAN IP should be inside of 172.100.0/24 then it's GW should be .1.

Toshi

Toshi_Esumi

Also, you need to/must have a site-to-site IPsec vpn or something else to reach LAN side of Site B from LAN side of Site A. Then proper static routes are needed on both sides through the tunnel. You haven't showed them yet.

Toshi

Yac

So you mean that the WAN of Fortigate 2 must be the LAN of Fortigate 1.

Yacer ALI
Yacer ALI
Toshi_Esumi

I guess I misread your original statement. You wrote "...a 2nd Fortigate, and have connected port 1 of Fortigate1 to the WAN1 of the second Fortigate". So "port1" is NOT LAN, is it?
Then I was wrong.
You can use a different subnet for the interconnection from 1st FGT's LAN, such as 10.1.10.0/30 as you described. Just share us the static routes as well as your VPN interface name, which should be used for the static routes.
You also need a pair of policies on both sides from&to the VPN.

Toshi

Yac

Thank you for your prompt reply.

You suggest that I use a VPN connection for the interconnection between the 2 fortigates.
Isn't the static route enough for this kind of connectivity?

Yacer ALI
Yacer ALI
Toshi_Esumi

Interconnection I mentioned above is between 1st and 2nd FGT connection at Site B.
The VPN is to connect Site A and Site B over the internet because you mentioned ISPs with NAT instead of a MPLS provider.

Toshi

Atul_S
Staff & Editor
Staff & Editor

Hi Yacer,

 

Its best if you could share the static routes configured for your setup, along with the  correct NAT mapping on both FGT and the correct security policy defined. 

 

Thanks,

Atul Srivastava
dingjerry_FTNT

Hi @Yac ,

 

1) "On site B, we have a 2nd Fortigate, and have connected port 1 of Fortigate1 to the WAN1 of the second Fortigate."

 

How did you connect FGT1 port1 to the FGT2 WAN1?  MPLS? Via a switch or router in the middle?

 

2) What is the IP assigned to the FGT1 port1?  There is no such info.

 

So based on your description, the network diagram seems like below:

 

ISP --> WAN (10.1.10.1) <--> FGT1 <--> Port1   ......    WAN1 (10.1.10.2)<-> FGT2 <-> LAN (192.168.1.1/24) <-> CCTV cameras

 

I don't know where I can put this info in this diagram:   Fortigate1 LAN IP address: 172.20.100.1/24

Regards,

Jerry
Yac

DIAGRAM FORTIGATE.jpg

 

Here's the diagram to summarize

Yacer ALI
Yacer ALI
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors