Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

putting wireless router on dmz

I know you should always try something before asking, but I am not on site yet. I have a new FG60B going in on a network this weekend. internal interface is 192.168.0.99 DHCP enabled on my FG60 Internal interface. We have some wireless laptops we want to access the internet but nothing else. We have an d-ling DI-624 wireless router, I wanted to put on the DMZ port of my FG60B. network/interface/dmz enabled but no values assigned. Any assistance greatly appreciated to get ths going.
21 REPLIES 21
FortiRack_Eric
New Contributor III

This should be pretty straighforward. Configure a seperate network segment on the DMZ like 172.16.0.1/24 disable DHCP on the wireless router. Enable DHCP on the DMZ port. range 172.16.0.20 - 172.16.0.99. Gateway and DNS server 172.16.0.1 Enable DNS forwarding from DMZ Add fw rule from DMZ to Wan1. configure the services you want to allow and attach protection profile. If you allow anybody to access your access point with no security it would seriously recommend to have strict protection profile and disallow SMTP. Cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Not applicable

I have followed the steps as outlined by Eric. I set the lan of the D-Link to 172.16.0.10 My laptop gets an IP. but no web surfing?
rwpatterson
Valued Contributor III

Check that the policy from the DMZ to external has NAT enabled. Run a trace from the laptop to see how far traffic gets before it fails.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Thank you Bob, that sorted it all out!
Check that the policy from the DMZ to external has NAT enabled.
Not applicable

Trying to do the same thing and I just cannot figure this out. Maybe I just don' t understand this router well enough. It' s a Fortigate 60, which I love. This thing has been rock steady. I have everything else setup just fine, though, and has been for more then a year. Never used a DMZ before, although I certainly understand what it is and what it' s used for. Help?!? This is what I' ve done. System > Network > dmz Bring Up > Edit Set ADDRESSING MODE > Manual - IP/Netmask This should be set to whatever the router is, no? or is this the " Separate Network Segment" Eric was referring to? Firewall > Virtual IP Create New > Name - DMZ Static NAT External IP is 66.*.*.* - an external ip addy that I own Mapped IP is set to the IP of the router. " Enable DHCP on the DMZ port" . No idea where to do this. System > DHCP > dmz > Relay ... but it wants an address? Can' t I just use the DHCP server from the Linksys wifi router I am trying to set up? Then I went to System > Firewall > Policy Create New & Enable. Source - dmz - all Destination - wan1 - all, always, any, accept NAT - checked My apologies for asking what should be a simple question, but I' ve spent far to much time trying to figure this out now, and I give up. Any help sincerely appreciated. Thanks for your time. Tony
rwpatterson
Valued Contributor III

Jeeez, there are a bunch of questions here.[ul]
  • Is the IP address on the FGT DMZ on the same subnet as that of the wireless device? (192.168.x.y/255.255.255.0 The x must be the same on the FGT and the wireless router)
  • Is the IP address on the wireless router a DHCP address or a hard coded one?
  • Who will be serving DHCP addresses? [/ul]On to the debugging... Can you ping the wireless device from the FGT? Can wireless devices ping the FGT? If the wireless router is serving DHCP addresses to it' s clients, you do not need to use the DHCP server on the FGT. That would be a good thing. Less complicated. Just make sure that you allow the address range that is being served access to the Internet. The VIP you created is only good for letting public entities into your network to the private server. Get rid of that. My suggestion: Let the Linksys serve out the DHCP addresses. Configure the Linksys to 192.168.x.1(/255.255.255.0). Configure the DMZ port on the FGT to 192.168.x.255(/255.255.255.0). Set the default gateway in the DHCP server on the Linksys to match the IP address on the FGT DMZ port. Plug the INSIDE port on the Linksys to the DMZ port, and you should be good to go. As far as DNS goes, I believe you could point it to the FGT as well, and the FGT will pass the traffic on to it' s defined DNS servers. That you' ll have to try out for yourself. If you kow your ISP' s DNS servers, insert them manually into the Linksys DHCP server. Good luck
  • Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    Not applicable

    Just wanted to say thanks for trying to help. Have been really sidetracked by some other stuff and haven' t been able to get back to this. I appreciate the time you gave to help me, and I will revisit this very soon. Thanks again!
    Not applicable

    Let the Linksys serve out the DHCP addresses. -Done. That' s what I intended. Configure the Linksys to 192.168.x.1(/255.255.255.0). - I used 172.168.1.1 My internal network is using 192 so I want completely different ip' s for the wifi. Configure the DMZ port on the FGT to 192.168.x.255(/255.255.255.0). - Do you mean 192.168.1.1? Didn' t think I could use .255? In fact, I try and it tells me I cannot. INVALID IP. System > Network > Edit DMZ > Addressing Mode = Manual and enter ip there. Again I used 172.168.1.1/255.255.255.0 Set the default gateway in the DHCP server on the Linksys to match the IP address on the FGT DMZ port. - Done Plug the INSIDE port on the Linksys to the DMZ port, and you should be good to go. - No joy. If you kow your ISP' s DNS servers, insert them manually into the Linksys DHCP server. - I did indeed use my ISP' s DNS servers. Got to be something simple I am missing here.
    rwpatterson
    Valued Contributor III

    Yes, I meant ...254. The Fortigate and the Linksys cannot both have 172.168.1.1. This is why I said set the FGT to ....254. The default GW on the Linksys should be ....254 as well as the DHCP server config. Away you go.

    Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors