Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Umesh
Contributor

why do we assign secondary IP address

Hi All,

 

I am little bit confused, why do we have to assign secondary IP address on the interface and what is the use of secondary IP address.

 

Regards,

Umesh

3 REPLIES 3
sagha
Staff
Staff

Hi Umesh

 

If you would like to have multiple IP address on the interface, you can make use of secondary IP addresses. This helps in configuring multiple subnets on the same interface. 

 

https://docs.fortinet.com/document/fortigate/6.0.0/handbook/915482/secondary-ip-addresses-to-an-inte...

 

Thank you. 

Shahan

Yurisk
SuperUser
SuperUser

Usually it is a temporary state, when for example switching topology , say from LAN 10.10.10.0/24 to 192.168.15.0/24 and you want to minimize downtime. Configuring new network on the FGT interface to LAN you can switch lans and both networks will work without changing something in the fortigate. 

https://yurisk.info
https://yurisk.info
ricky_andre_76
New Contributor II

another use case could be the following: you need access to the internet, but the p2p subnet between the FW and the router needs to be private, so that it can't be attacked from the internet. Then you configure a public secondary ip, and use it for VPNs or sdwan.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors