Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GregH
New Contributor

Switch to INterface Mode and Internet Access

Ok, I am new to the Fortinet series of FW and I just installed a 60C. It has been a challenge and I have a few questions. 1. I am trying to switch to the Interface Mode that will allow me to assign individual subnets to each port. I have reset the 60C to all of the defaults but when I try to switch out of the Switch mode I always get an error that says " Entry in Used" . I had read on this forum to delete the DHCP associated with the interface and delete the policy for the interface. When I did this I got a connection error and could not log onto the 60C at all so I had to reset again. What are the steps to setup a default 60C to the interfce mode from the reset system defaults? 2. I am getting very spotty internet access. It seems like only one machine can connect to the internet at one time. I am getting a DHCP from my ISP but no luck getting out on all the machines. It appears that all the machines on the wired side are getting the correct IP addresses but cannot get out. I see the firewall rule set that allows all to go out. Is there an incoming rule that needs to be set? Thanks in advance, Greg H.
13 REPLIES 13
GregH
New Contributor

Found it, Google. This is driving me crazy. I have no sophisticated setup and right now all that I want to do is to access the internet. The WAN1 network is set to DHCP and is getting the correct information and the DNS server addresses. I have the router behind my current router so that I can get it setup because I have to have internet access for the family while I am configuring it. It appears that the router is getting something as my maintenace information is showing up correctly in the status widdow unless this was put into the router when I purchased it. I cannot get out to the internet when I press the LogIn button on the maintenance screen though. I have added my less expensive CheckPoint Z100G router hooked up in the same fashion as the Fortigate, via a switch to the main router, and it works flawlesly without even changing any settings. I can access the internet through wireless or wired. When I connect to the Fortigate via a wired or wireless connection I get the infamous Windows 7 setting of " Unidentified Network" I am getting the correct DHCP address from the Fortinet 60C in either wired or wireless but cannot get out ot the internet. The firewall rules are set for each interface to allow all to go to the WAN1 interface. I do not have any incoming rules set at this point. Any other thoughts? Thanks in advance, Greg H.
ede_pfau
SuperUser
SuperUser

Hi, to get you up and running: Using DHCP on the wan1 port should give you - the DNS address - a valid IP - a default route / a gateway If you don' t see a default route pointing to your DHCP server (the other router), in Route>Monitor, then you have to add it manually - this depends on how you set up the DHCP options in the other router: dest=0.0.0.0/0 gateway=192.168.168.168 I can understand that you are a bit frustrated setting the FG up. IMHO you made your life more difficult than necessary: - you have no experience with Fortigates, nor with firewall appliances in general. But you assume they are as easy to setup as a simple DSL router. - you haven' t read the docs. If I had no idea about an appliance I would read at least the introduction and a sample setup. Why do people assume that a high sophisticated security device is best installed with no prior knowledge, and handbooks are for whimps?? I' ll never get that. Get the docs at http://docs.fortinet.com Step-by-step example e.g. in the FortiOS Handbook for 4.00MR2, pp. 289 " Small Office Network Protection" . You can leave out the parts you don' t need. - you setup a major network device while not being able to interrupt live traffic. What you are configuring now will have limited use once you' ve eliminated the old router. So you start over again, at least to a certain part. No you can' t setup a router/firewall without some network downtime. Only magicians can. - you look for help on a Sunday. This is probably the least busy day on the Forums. Nevertheless, with some reading and understanding of the basic concepts you should be able to get your network connected.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
rwpatterson
Valued Contributor III

The gateway is the next hop router, not your own. Change that to interface address on the Fortigate, not the ISPs address. For WAN1 that is taken care of. Make sure all policies facing the Internet have NAT enabled. For troubleshooting, try a simple PING to 8.8.8.8. If PING works and browsing does not your problems is 100% DNS. If PING does not, try a traceroute and see how far you get before it blows up. Just because IE fails doesn' t mean the Internet is down... Also, the static route is redundant. Get rid of it.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
GregH

Bob, Thank you very much for your post. As it turns out I discovered this last night and got the FW working with just the changes that you said to do. Critical oversight on my part. I have all of my interfaces configured now and it appears that all computers etc. are are receiving the correct IP addresses. Before I take my Sonicwall NSA 240 out of service I am going to make sure that all is working well and I get the UTM set up correctly for my needs. Greg
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors