Hi all,
Actually I'm testing my new fortigate 60f and for test I have this configurations:
modem -> oldFirewall (wan ip 10.0.0.10; lan 20.0.0.1) -> fortigate (wan ip 20.0.0.10; lan 192.168.10.1)
I can can connect to forticlient but actually I cannot ping any device in the same subnet of wan connection. for example I cannot ping 20.0.0.20-254 devices)
can some one help me which setting let clients to reach all devices also that devices connected to the old firewall?
many thanks in advance
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
So you mean switch1 is L3 and the IP 30.0.0.1 is owned by that switch, right?
If this is the case then you have two choices:
Hi
Add the following firewall policy:
Then connect to SSL VPN again and it should work.
many thanks in advance...just one more question. I'm trying set policy but I can't find wan option
can you help me?
If I understand what you mean, you need to create an address object by clicking the "+ Create" button shown on your screenshot, then create an address object (lets call it "s-wan1") of type subnet with the value 20.0.0.0/24.
many many many thanks
it works...just one more question
if I have some machines with static ip 30.0.0.10 30.0.0.20 etc but I don't have any lan or wan on that subnet, how can i reach them in forticlient? I try adding the policy as myou suggest to me before, but I cannot reach them. these devices are just statics devices which I can reach adding on my laptop the adding gateway 30.0.0.1
there is a way to reach them connecting them to fortigate? many thanks again for your help
Do you mean that these devices are not directly behind FortiGate but are behind another router which is connected to FortiGate? In other words do you mean FortiGate doesn't have any interface with address 30.0.0.x/24?
Are you using public IP addresses on your network (20.x.x.x, 30.x.x.x)?. If this is the case than this is wrong, you have to use private addresses otherwise.
I have this situation:
modem -> router -> fortigate (not lan dhcp server until now) -> switch1
some machine with static ip (30.0.0.10...ecc/24) -> switch1
how can reach machines with static ip and gateway 30.0.0.1? I need ad a lan interface in the fortigate?
So you mean switch1 is L3 and the IP 30.0.0.1 is owned by that switch, right?
If this is the case then you have two choices:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.