Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Technigogo
New Contributor

Configure Google Fiber static IP s on FortiGate 80F

The client had a single IP from Google Fiber before my company took over support. We installed an 80F, and the "static" is issued by DHCP from Google Fiber on the WAN interface. We have upgraded their Google Fiber account to add 5 static IPs. The statics are in a different subnet. 

 

I am unsure what to do. Very important - if I create VLAN(s) for the static IP(s), what will change for the static IP issued by DHCP over the WAN? All traffic is currently using that DHCP static IP, including VPN. Will that render that IP unusable since it becomes a gateway for the block of static IPs?

 

If the statics require VLAN, what interface? the main LAN or the WAN? What is the Role that I select: LAN? WAN? DMZ? Undefined?

 

Can this be done with VIPs or IP Pools? If IP Pools, what type do I use? One-to-One, Fixed-Port Range, or something else?

 

Here is Google's depiction of the necessary layout for using static IPs.

Technigogo_0-1687961380285.png

 

 

 

1 Solution
Toshi_Esumi

Google's doc or any other ISP's would NOT include a case their customer has a FW to terminate the circuit. Never assume they're used as VIPs. Their explanation, as the diagram indicates, assumes a "router" terminates the circuit, let's say a cheap Linksys or TP-Link router, which can only route the additional subnet to LAN side. In that case, you have to assign it on the LAN interface.

With VIPs, the additional public IPs never leave the FGT. Just stay inside of it.

 

If you still have some doubt, you can configure a VIP to one device, get a maintenance window, then swap it with the current router/FW they have then verify it actually works.

 

Or open a ticket at TAC and ask them. They would say exactly the same.

 

Toshi

View solution in original post

12 REPLIES 12
Toshi_Esumi
SuperUser
SuperUser

I've never seen that kind of helpful diagram provided by any ISPs who offer additional static IP blocks before. That tells exactly what you can do with the additional /29 subnet. Let's say you got 1.1.1.0/29. Then you can use 1.1.1.1/29 on your 80F's LAN interface IP, then other devices that should get a public IP take like 1.1.1.2/29 - 1.1.1.6/29 each. Of course the GW for those devices is 1.1.1.1.

 

Toshi

Technigogo

Thanks, Toshi.

 

Where do I put the 1.1.1.1 then? As an additional IP on the existing LAN interface or does this have to be a VLAN?

What do you make of the 23.23.23.23 reference in this part of the diagram?

23232323.png
Toshi_Esumi

It's up to you or what the customer currently has/previously had. If no private IP needed, you can swap the "internal" interface IP 192.168.1.99/24 with 1.1.1.1/29. If you want/need it as a separate subnet, either need to use the secondary IP on the internal or a new VLAN interface. 

Technigogo

Is this the right way to do this?

 

  1. I set the 1.1.1.1/29 as a Secondary IP on the existing LAN Interface.
    secondaryIP.png
    LANinterface.png
  2. Set the Public static IPs of 1.1.1.2 to a VIP, setting the Interface to internal, Static NAT,   mapped to the desired LAN IP.
    VIP.png

 

Toshi_Esumi

If you want to use them in VIPs only, you don't need to have it on any FGT's interfaces. Only in case the devices need to have one of public IPs, you need to set it at an interface.

Technigogo

I don't understand. Here is the information from Google regarding this configuration. Specifically, the highlighted text.

googleIPinfo.png

Toshi_Esumi

Google's doc or any other ISP's would NOT include a case their customer has a FW to terminate the circuit. Never assume they're used as VIPs. Their explanation, as the diagram indicates, assumes a "router" terminates the circuit, let's say a cheap Linksys or TP-Link router, which can only route the additional subnet to LAN side. In that case, you have to assign it on the LAN interface.

With VIPs, the additional public IPs never leave the FGT. Just stay inside of it.

 

If you still have some doubt, you can configure a VIP to one device, get a maintenance window, then swap it with the current router/FW they have then verify it actually works.

 

Or open a ticket at TAC and ask them. They would say exactly the same.

 

Toshi

Technigogo

Toshi, I fully appreciate how much you are trying to help me. I am testing several scenarios now in my own environment.

Toshi_Esumi

In case you didn't know, you can use full /29 8 IPs for VIPs, including 1.1.1.0/29 and 1.1.1.7/29. Goodle side routes all packets destined to the subnet including the subnet address and broadcast address. Only in case you assigned it to a LAN interface those IPs wouldn't be usable/routable.

 

Toshi

Labels
Top Kudoed Authors