Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

putting wireless router on dmz

I know you should always try something before asking, but I am not on site yet. I have a new FG60B going in on a network this weekend. internal interface is 192.168.0.99 DHCP enabled on my FG60 Internal interface. We have some wireless laptops we want to access the internet but nothing else. We have an d-ling DI-624 wireless router, I wanted to put on the DMZ port of my FG60B. network/interface/dmz enabled but no values assigned. Any assistance greatly appreciated to get ths going.
21 REPLIES 21
Not applicable

No joy. I think I know what the issue is. The router I am using is basically your average home-use type Linksys router. Mine. Wanted to make sure I could get this to work before I actually purchase a router for the office. I set the Def GW for the router, but there is no way for me to set the Def GW for the Lnksys DHCP server. These are my choices under DHCP: Local DHCP Server: Enable, Disable Starting Addy # of addys Lease time. WINS That' s it. So I need a REAL router. Need to use the Def #' s. Or need to set the FGT to do all this as mentioned at the top of this thread. Sound right?
Not applicable

Well, wait... the OP is using a DI-614. That' s the same kind of router. Tried Eric' s method, too. Laptop connects with LIMITED OR NO CONNECTIVITY and a 169.254.. address. - Configure a seperate network segment on the DMZ like 172.16.0.1/24 What is the /24 at the end of that? I used .1.
rwpatterson
Valued Contributor III

The DI-614 is a very good router. I have a DI-604, and am very happy with it. I do see your issue though. It forces itself to be the gateway. The only other way which may complicate things a bit, would be to turn on DHCP on the DMZ interface (or just hard code the two IP addresses!), and plug the WAN port of the DI-614 into that. This way, the DI-614 will think it' s connected to your ISP, and there will be an interim route betwen your Fotrtigate and the DI. Make sure that the DHCP on the DMZ port is not the same subnet as the one on the inside port of the DI. This should work with a small bit of complictaion due to the new hop in between the two.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
FortiRack_Eric
New Contributor III

the /24 is the subnet mask. 255.255.255.0

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
rwpatterson

Forgot to mention that. Doh!

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Really feeling like an idiot here. I am trying to set it up as Eric said. This is all correct, yes??
rwpatterson
Valued Contributor III

Looks 100% to me. Make sure that the D-link is in that same subnet, but outside the range of DHCP address leases.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Thanks for the help everyone. Really appreciate it. I don' t know why I didn' t think of this earlier: Hey, let' s remove the LINKSYS (not a D-Link fellaz) and plug right in to the DMZ and see if it works. It does, just fine. So I' ll take my Linksys home and just buy a WAP for the office. Anyone have a favorite WAP? Y' all link the D-links, eh?
Not applicable

This is what I am doing, and it works (most from Eric) Key thing is it does not appear to work with WEP, so I set it to WPA. Configure a seperate network segment on the DMZ like 172.16.0.1/24 disable DHCP on the wireless router. Enable DHCP on the DMZ port. range 172.16.0.20 - 172.16.0.99. Gateway and DNS server 172.16.0.1 Enable DNS forwarding from DMZ Add fw rule from DMZ to Wan1. configure the services you want to allow and attach protection profile. Ensure that the policy from the DMZ to external has NAT enabled. If you allow anybody to access your access point with no security it would seriously recommend to have strict protection profile and disallow SMTP. Plug Wireless internal network to the DMZ port on the FORTIGATE. **NOTES Feb 6/08 It seems to work best for the route to be set to WPA or better. I have found WEP does not work properly.
Not applicable

I got a Dlink WAP. Plugged it into the DMZ. I was online in less then 5 minutes with WPA encryption. Didn' t try WEP. So all my problems were from that router.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors