Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dbeitler
New Contributor III

Would like to configure a physical port on an 601e for local management

The 601e only has a single management port.  I would like to configure one of the 1G physical ports, or something else, for management purposes. I ran across "https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/313152/out-of-band-managemen... and "https://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-Reserved-Management-Interface/ta-p/1901...".  Are these the best approach?  I don't need or want to be able to access this remotely.  Simply for those times when someone is physically present, they can connect a device, and have access to the GUI/CUI without having to swap any existing management cable connections, and without having to go over the network.

Note there are two 601e units in an HA configuration and is in a secured location.  If it matters, it is also connected to FortiManager.

 

2 REPLIES 2
dingjerry_FTNT

Hi @dbeitler ,

 

1) You can follow the KB article to configure the HA management interface so you can access either device locally or remotely via the network to which the HA management interface IP belongs.

 

2) "I don't need or want to be able to access this remotely.  Simply for those times when someone is physically present, they can connect a device, and have access to the GUI/CUI without having to swap any existing management cable connections, and without having to go over the network."

 

I don't really understand this.

 

As long as you have the IP info configured on one interface, you can connect a laptop directly to that interface and configure an IP from the same subnet to access FGT GUI.  Of course, you have to enable HTTP/HTTPS admin access on this interface.

Regards,

Jerry
gopekto2
New Contributor

Nope. It’s a firewall, not a switch. There’s no vlan across multiple ports with different states on each of the ports like a switch. Use a switch for this. Fortiswitch can do this perfectly, and is full integrated into the FortiGate as essentially additional interfaces.

router login 192.168.l.l
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors