Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
laf
New Contributor II

Vip with different addresses

I have a single public IP set on wan1 from a FG 100A, let s say from class alfa. Also I have a subclass of IPs from another class: beta. I have to create port forwards for some internal servers connected to internal. The client wants to use all the IPs from class beta. I created all the VIP and firewall policies. Tomorrow I have to insert the equipment into the client' s network. The question: do I have to add the IP' s from class beta as Secondary IP to wan1 10x in advance, laf.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
2 REPLIES 2
rwpatterson
Valued Contributor III

Logically speaking, if those class beta IP' s are being sent to the FGT, then no. Worst case would be to put a secondary IP in that range on the external interface. Good luck

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
laf
New Contributor II

I shall answer to this after real implementation was made. There s no need to add the beta class IPs as secondary. It works without it, too.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
Labels
Top Kudoed Authors