- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
info
Hi everyone, I wanted to ask you for some info. I would like to connect a customer's connectivity to our fortigate 100F, using the DHCP feature and using the same subnet he provided us. How could I connect it all? Thanks in advance to anyone who will give advice
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Do you have a diagram on how this topology should look?
Are we talking external connectivity here i.e over a WAN using public IP ranges or is this internally via a VPN Site-to-Site link to customers?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the supplier brings us a connectivity and a router.
The vendor only gave us the subnet and dns.
This subnet is locked down and only reaches certain addresses.
I wanted to hook this connectivity to our firewall to be able to route the traffic by differentiating the routes but using the client's declared subnet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Not sure I fully understand - but it seems like you need to do this:
Define a port on the FortiGate i.e port1 and connect this to the customer provider router.
On the interface settings for port1, give the FortiGate an IP within that provided range.
Lets say your customer provided you with 192.168.10.0/24 - give the firewall 192.168.10.1 lets say.
After configuring the port, you should be able to route to your customers network.
If I have misunderstood, please can you show a diagram
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't know if it's clear
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Okay - main things here:
Your client LAN subnet is the same as the subnet provided over the MPLS. This isnt going to work.
If the network over the MPLS is completely separate to your LAN, you need to ideally change your LAN subnet.
Then, you can connect the MPLS network to the firewall on the 192.168 range, and then have a separate network on your LAN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the problem is that the applications respond to that ip class... suggestions?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Applications respond to that IP class? huh?
If anything, just move your client network to 192.168.2.0 then - same class, just different network.
I am not too sure on the applications not responding to IP classes though - that seems odd.
