Hi All
I am at initial phase of a SDWAN deployment. I will have dual FWs in branches. I can connect my internet connection as full mesh to my fortigates. However my mpls provider is proving only one physical connection with /30 subnet. So i can connect it only to one device. Can i do some magic to make fortigates to share my mpls link for sdwan?
The only way I know of is to add a switch in between. It does add a single point of failure but you're already looking at that with the provider's setup. This is what we do, as our ISP's only give us one port each.
Hi
as mentioned by @lobstercreed
you need fortiswitch or any other l2 switch that support stacking.
create a vlan in switch and add 3 port to that vlan in access mode.
example:
port 1
port2
port3
in vlan 2 with access mode. connect MPLS to port 1 and from port 2 to 1st firewall and port3 to 2nd firewall
Regards
Mahesh
But ISP is giving me /30. Will firewalls share the only one available IP?
Yes, if they are in HA, which was my assumption since you said dual FWs. Are they not HA? If not, why not?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.