Hi,
I have 4 public IP's given by our Internet supplier and I'm wondering if there is any way to push them thru Fortigate 100D LAN ports without NAT. I want to avoid the installation of another switch in between the ISP box and my firewall, in order to assign the 4 public IP's to another devices that I have on the plant.
Thanks,
Paul
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hey Paul,
It's pretty tough to answer that exactly or with efficiency in mind without knowing the rest of your setup. I'm taking a LOT of guesses
I'm not too familiar with the 100D - but on my devices that I have all over the place I can assign a particular node with an external IP by creating an interface with the range that you have, then create objects for each external IP and map that to the VLAN. That brings layer 2 to a layer 3 object and you can still use Application Sensors / IPS etc.
Anyone can feel free to correct me if I'm wrong. I know I have at least 1 endpoint configured directly with an external IP and from memory thats how I did it. VLAN object -> Single IP Object within range on Interface -> ISP.
I would also look to see if you can use NAT and internal addressing. It'll probably save you headache down the road. My $0.02 and I'm FULLY aware I'm still learning.
FCNSP
-------------------------------------
"They have us surrounded again, those poor bastards."
-Unnamed Medic
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.