FGT60B, FGT100A, FGT100D
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
IP/Mask Gateway Device Distance 0.0.0.0/0.0.0.0 A1.B1.C1.D1 wan1 10 0.0.0.0/0.0.0.0 A2.B2.C2.D2 wan2 10I have also one policy route to make WAN1 as preferred link:
Incoming Outgoing Source Destination internal wan1 0.0.0.0 / 0.0.0.0 0.0.0.0 / 0.0.0.0I have doubled firewall policy internal -> wan1 and internal ->wan2 I have set ping servers to check if link is alive. Everything works fine but second internal IP doesn' t work. My firmware is: 3.00-b0670(MR6 Patch 3) Earlier it was 3.00-b0668 and there was the same problem. rwpatterson, all I want is to have two subnets with one device as internet gate. I do not want to see computers from one subnet to another. I only want to FortiGae act with two internal IP addresses and allow traffic from both subnets to internet.
FGT60B, FGT100A, FGT100D
IP/Mask Gateway Device Distance 0.0.0.0/0.0.0.0 A.B.C.D2 wan1 10No polisy routes. One firewall policy:
internal -> wan1 ID Source Destination Schedule Service Profile Action 1 all all always ANY ACCEPTIn routing monitor I see:
Type Subtype Network Distance Metric Gateway Interface Static 0.0.0.0/0 10 0 A.B.C.D2 wan1 Connected 10.0.0.0/24 0 0 0.0.0.0 internal Connected A.B.C.D1/29 0 0 0.0.0.0 wan1 Connected 192.168.0.0/24 0 0 0.0.0.0 internalWAN2 interface is now disabled. I rebooted FortiGate. Form my primary subnet (my PC have only one IP address: 10.0.0.x and 10.0.0.1 as default gateway) I can accesss to internet. I can ping to FG using 10.0.0.1 an I can ping to FG using 192.168.0.1 too! From test computer (with only one IP address 192.168.0.x with 192.168.0.1 as default gateway) a can`t ping to 192.168.0.1 and I can`t go to the internet. I try with overlap enabled and disabled and always nothing.
FGT60B, FGT100A, FGT100D
From test computer (with only one IP address 192.168.0.x with 192.168.0.1 as default gateway) ...I just made simple test: I connected notebook with manualy set one IP address (192.168.0.x) straight to FG (other internal port) and it`s the same situation. I should have allow-overlap enabled or disabled?
FGT60B, FGT100A, FGT100D
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
FGT60B, FGT100A, FGT100D
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.