I'm very new to networking, and I'm a bit over my head. The current situation is we have two firewalls (Firewall 1 and Firewall 2) and two different WANs (VDOM Prod = 1.2.3.4/32, VDOM Nonprod =5.6.7.8/32) on physical ports on Firewall 1. There are no WAN connections are Firewall 2, so when there's a failover, we lose connection to the outside.
My end goal is to have a physical port on each that can support both VDOM WANs without adding more physical WAN drops to the greater network.
So, here is my concept:
Firewall 1:
Physical Port-1 1.2.3.4/32 (Prod VDOM)
VLAN 5.6.7.8/32 (NonProd VDOM)
Firewall 2
Physical Port 2 5.6.7.8/32 (NonProd VDOM)
VLAN 1.2.3.4/32 (Prod VDOM)
Is this a feasible solution? Should I make the connection identical?
Thank you for your time.
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Thanks,
hi,
are the firewalls connected in a cluster/ha configuration?
if so, they would need to have identical physical connection, meaning port1 and port2 from FW-2 should have a similar connection as port1 and port2 from FW-1, in a switch either a stack/vpc or a single unit switch .
User | Count |
---|---|
2568 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.