I have a customer who tells me he is going to use Fortigate 90D's
there is a SPT fibre ring with 2 x Fortigate 90's connected
the 90D's need to act as one i.e. VRRP
they also need to NAT to the inside also with VRRP on the inside interfaces
and they need to also support a DMZ also with VRRP
never used Fortigate before, will they do this ?
Not sure what you mean NAT to the inside but vrrp is supported. Is your NAT a SNAT or DNAT or combination of the two?
Ken Felix
PCNSE
NSE
StrongSwan
The diagram looks exactly like HA a-p setup if you replace the VRRP cable with a heart-beat cable. I'm not sure how the fiber-ring would work with VRRP-connected two FGTs.
it would be static NAT
forgot to mention that the ring has a load of VLAN's on it
in the past when i have done this i would usually use 2 switches on the ring and then connect each switch to both firewalls
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.