- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Two lan, one wan
Hi, I'm new in Fortinet world.
I have set two lan on two different ports on my Fortigate 60s ,v7.2.8 build1639 (192.168.1.x and 192.168.21.x). But one of them is not able to go in internet. How have I to set the correct gateway on wan1, wich works for one of them?
Thank you a lot
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @gianlucats,
I believe Toshi is referring to Firewall Policy. If one lan can get to the Internet, it means wan connection is working. You just need to make sure you have firewall policies to allow outbound traffic from both lan.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
somehow I logged on with a different profile. That @TE is me.
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please share the firewall policy of your firewall for those 2 interfaces (Working vs non-working)?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. For WAN gateway your ISP shoudl provide you the WAN IP/ Subnet and gateway.
2. You can configure a default route as
config router static
edit 1
set gateway IP_From_ISP
set device "YOUR_WAN_PORT (May be wan1 for 60e)"
next
end
3. Finally you need 2 firewall policies from your 2 LAN interfaces to the WAN port
https://docs.fortinet.com/document/fortigate/7.0.0/ngfw-deployment/99015/initial-setup
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I' ve not given all the infomation to you: on wan 1 there is a modem/router giving access to internet (192.168.123.254), sorry.
Thank you for be patient with a newbie :)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you have only one circuit on the FG60x and one LAN can get out to the internet, the circuit and the routing/gateway configuration is fine.
Most likely a proper policy doesn't exist for the second LAN.
Please share us your policies if possible.
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, thank you for answer.
Here you have
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @gianlucats,
I believe Toshi is referring to Firewall Policy. If one lan can get to the Internet, it means wan connection is working. You just need to make sure you have firewall policies to allow outbound traffic from both lan.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes. One menu above "Firewall Policy".
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
somehow I logged on with a different profile. That @TE is me.
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please share the firewall policy of your firewall for those 2 interfaces (Working vs non-working)?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you a lot guys.
I'm coming back home from work trip tonite and I'll try solutions. I keep you update!
![](/skins/images/EC9FF2F7BE06D4243426EA19DD2C8052/responsive_peak/images/icon_anonymous_message.png)