- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VIP for PLC and a Data collector that are in different VLANs
Hi,
I was wondering if someone can help me on this. I am very new to networking and would like to check if I can do IP address translation on a layer 2 device with address 192.168.199.2 on my VLAN2 going to VLAN 1 with subnet 10.156.116.0/22. My intended translated address is 10.156.119.2 for this layer 2 device and will be using a kepserver ex v6 device from the vlan 1. Hope someone can assist me. Thanks
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Technically according to the information about vlan1 the PLC device is on subnet 10.156.116.0/22 which means its gateway should be the vlan1 interface ip address. IF the PLC device truely have no gateway configured there is no way for it to know where to send packets. As far as the fortigate goes the configuration recommendations shared previously should offer NATing the source address 192.168.199.2/32 to be 10.156.119.2 before the traffic goes out to destination however that destination device need to have it is address and gateway setup otherwise that packet would never get reply. I recommend checking with the vendor of the PLC device what is the proper network setup and requirement. Remember also that you are using VLAN configuration here that means that device have to have a vlan setup as well as the switch that connects that subnet to the firewall.
Thank you,
saleha
- « Previous
-
- 1
- 2
- Next »
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @carlaranzaso ,
If the PLC has no GW configured, I am not sure whether it can talk to other networks or not.
You have to run the following command on FGT to confirm:
diag sniffer packet any 'icmp and host 192.168.199.2' 4
Then run Ping to 10.156.116.1 on the PLC device. If you can see the Ping packets coming to FGT, it should be working for your case. It doesn't matter if Ping does not work. We just want to see whether the Ping packets (ICMP Request) coming to FGT or not.
BTW, in your scenario, you have to use VIP, not IP pool.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Technically according to the information about vlan1 the PLC device is on subnet 10.156.116.0/22 which means its gateway should be the vlan1 interface ip address. IF the PLC device truely have no gateway configured there is no way for it to know where to send packets. As far as the fortigate goes the configuration recommendations shared previously should offer NATing the source address 192.168.199.2/32 to be 10.156.119.2 before the traffic goes out to destination however that destination device need to have it is address and gateway setup otherwise that packet would never get reply. I recommend checking with the vendor of the PLC device what is the proper network setup and requirement. Remember also that you are using VLAN configuration here that means that device have to have a vlan setup as well as the switch that connects that subnet to the firewall.
Thank you,
saleha
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Saleha, i followed your recommendation and did NAT on the device with gateway configuration instead of the PLC and it worked.

- « Previous
-
- 1
- 2
- Next »