I'm looking to configure BGP on my FortiGate 101F to establish a Dual-Homed connection. I have a /22 class of Public IPs and would like to create a Virtual IP (VIP) for each server to allow access from both WAN1 and WAN2. In the event that WAN1 experiences an outage, I want the servers to continue responding via WAN2. However, each customer is assigned a single Public IP, and I cannot allocate additional Public IPs for creating secondary VIPs.
My question is, how can I set up a single VIP for each server that works seamlessly with both WAN interfaces? I want to ensure that the servers can respond via WAN2 when WAN1 is unavailable. Your insights and guidance would be greatly appreciated.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @amini2425,
Why can't you create multiple VIPs? one to NAT the public IP of wan1 to an internal server and another one to NAT the public IP of wan2 to an internal server. If you want to create only 1 VIP, you can set the Interface to "any" and "External IP address/range" to 0.0.0.0.
Regards,
You said dual-home. I'll take it as "multi-home" with the /22 public subnet advertised by BGP to two circuits/ISPs. Then, the /22 subnet is not bound to either wan1 or wan2. Depending on how you advertise the /22 toward two BGP neighbors over two circuits, some might come in wan1 while others might come in wan2 for the same IP. So you just need to make the interface "any" for each VIP as @hbac said.
But if the public IPs are for your customers, I would suggest you chunk them up and assign each /31 or /30 to customers and route them to their interfaces.Which is more flexible for your customers to use assigned IPs.
Toshi
ok. I didn't know about the definition of "dual-home" until now. So those two circuits are provided by one ISP. Still the same IP can be routed either circuit if you are to advertise the /22 via BGP. So one IP in the /22 is not bound to a particular circuit/interface.
@amini2425
You can also create only 1 VIP for both WAN interfaces but in some specific cases.
This is when VIP IP range is not configured on any of WAN interfaces, and both ISPs know how to route traffic to that particular IP.
For example:
WAN1 IP 10.10.10.33/29
WAN2 IP 20.20.20.66/29
VIP IP: 30.30.30.5/28
Both ISPs should have route to 30.30.30.5 toward your device.
In this case you may use the same VIP on both WAN interfaces.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.