Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Hamza_derbali
New Contributor

L2 communication spanning two firewalls

Hello,

 

I have the architecture outlined bellow, and communication needs to be established between the machines on the network 10.1.2.0/24 via FW 1 (Palo alto) and FW2 (fortigate). Any suggestions or insights on how to achieve this would be highly valued.

 

hamza_d_0-1714779769190.png

 

Thank you.

 

 

7 REPLIES 7
ramlinga1
New Contributor

I've used a separate network for [similar to] this in the past, subnetted with 255.255.255.252 so that only two hosts are allowed on the link. Not sure if it was the best way, but it worked https://tutuapp.uno/ .

AEK
SuperUser
SuperUser

Hi Hamza

At both firewall levels, you need either transparent VDOM or virtual wire pair.

It is available with FG and I guess PAN can do it as well.

https://docs.fortinet.com/document/fortigate/7.4.0/ips-architecture-guide/748610/transparent-mode

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/166804/virtual-wire-pair

 

AEK
AEK
Hamza_derbali

Hello @AEK ,

 

the first is a FortiGate firewall in NAT mode, while the second firewall is a Palo Alto. Unfortunately, I lack the capability to transition to a transparent mode.

AEK

You don't need to convert the whole firewall to transparent mode, you can just create a transparent VDOM for that.

But the best solution I think is to correct your network to avoid this situation of having same subnet twice.

AEK
AEK
talrejakit
New Contributor

I did this after I bought a firewall for a client and they didn’t inform me they’ve also been working with another local IT guy and I found a newer firewall placed in a mechanical room I didn’t know existed. My firewall now is their VPN concentrator, so at least it makes it easy for me to manage their VPN and NAS.

Hamza_derbali

hello @talrejakit ,
Could you provide a diagram to facilitate better understanding?

hbac
Staff
Staff

Hi @Hamza_derbali

 

So you have 2 physical ports, one connected to the switch and one connected to 10.1.2.2. It is possible to put both ports in the same hardware switch and they will be in the same subnet. 

 

Regards, 

Labels
Top Kudoed Authors