Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Umesh
Contributor

why do we assign secondary IP address

Hi All,

 

I am little bit confused, why do we have to assign secondary IP address on the interface and what is the use of secondary IP address.

 

Regards,

Umesh

3 REPLIES 3
sagha
Staff
Staff

Hi Umesh

 

If you would like to have multiple IP address on the interface, you can make use of secondary IP addresses. This helps in configuring multiple subnets on the same interface. 

 

https://docs.fortinet.com/document/fortigate/6.0.0/handbook/915482/secondary-ip-addresses-to-an-inte...

 

Thank you. 

Shahan

Yurisk
SuperUser
SuperUser

Usually it is a temporary state, when for example switching topology , say from LAN 10.10.10.0/24 to 192.168.15.0/24 and you want to minimize downtime. Configuring new network on the FGT interface to LAN you can switch lans and both networks will work without changing something in the fortigate. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
ricky_andre_76
New Contributor II

another use case could be the following: you need access to the internet, but the p2p subnet between the FW and the router needs to be private, so that it can't be attacked from the internet. Then you configure a public secondary ip, and use it for VPNs or sdwan.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors