Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gianlucats
New Contributor III

Two lan, one wan

Hi, I'm new in Fortinet world.

I have set two lan on two different ports on my Fortigate 60s ,v7.2.8 build1639 (192.168.1.x and 192.168.21.x). But one of them is not able to go in internet. How have I to set the correct gateway on wan1, wich works for one of them?

Thank you a lot

 

3 Solutions
hbac

Hi @gianlucats,

 

I believe Toshi is referring to Firewall Policy. If one lan can get to the Internet, it means wan connection is working. You just need to make sure you have firewall policies to allow outbound traffic from both lan.

 

Regards, 

View solution in original post

Toshi_Esumi

somehow I logged on with a different profile. That @TE is me.

Toshi

View solution in original post

Mrinmoy
Staff
Staff

Can you please share the firewall policy of your firewall for those 2 interfaces (Working vs non-working)?

Mrinmoy Purkayastha

View solution in original post

9 REPLIES 9
Mrinmoy
Staff
Staff

1. For WAN gateway your ISP shoudl provide you the WAN IP/ Subnet and gateway.

2. You can configure a default route as 

 

Satic route.JPG

config router static
edit 1
set gateway IP_From_ISP
set device "YOUR_WAN_PORT (May be wan1 for 60e)"
next
end

 

3. Finally you need 2 firewall policies from your 2 LAN interfaces to the WAN port

https://docs.fortinet.com/document/fortigate/7.0.0/ngfw-deployment/99015/initial-setup

Mrinmoy Purkayastha
gianlucats
New Contributor III

I' ve not given all the infomation to you: on wan 1 there is a modem/router giving access to internet (192.168.123.254), sorry. 

Thank you for be patient with a newbie :)Screenshot 2024-06-01 132559.pngScreenshot 2024-06-01 132459.png

Toshi_Esumi
SuperUser
SuperUser

If you have only one circuit on the FG60x and one LAN can get out to the internet, the circuit and the routing/gateway configuration is fine.
Most likely a proper policy doesn't exist for the second LAN.
Please share us your policies if possible.

Toshi

gianlucats

Hi, thank you for answer.

Here you have

Screenshot 2024-06-01 132559.png

hbac

Hi @gianlucats,

 

I believe Toshi is referring to Firewall Policy. If one lan can get to the Internet, it means wan connection is working. You just need to make sure you have firewall policies to allow outbound traffic from both lan.

 

Regards, 

TE
New Contributor

Yes. One menu above "Firewall Policy".

Toshi

Toshi_Esumi

somehow I logged on with a different profile. That @TE is me.

Toshi

Mrinmoy
Staff
Staff

Can you please share the firewall policy of your firewall for those 2 interfaces (Working vs non-working)?

Mrinmoy Purkayastha
gianlucats
New Contributor III

Thank you a lot guys.

I'm coming back home from work trip tonite and I'll try solutions. I keep you update!

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors