Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cstan1989
New Contributor

Every departments using different internet line to access internet

Hello Everyone,

 

I am planning to configure each departments to access internet with different internet line.

 

Below is the step in my mind, hope all of you can give some advise.

- Create WAN LLB with Volume mode, weight put 0 for every WAN interface.

- Create WAN LLB Rules:

    - Source Address=All

    - Users Group=Departments

    - Destination Address=All

    - Protocol=Any

    - Outgoing Interface=Preferred WAN interface

- Create IPv4 Policy, Internal LAN to WAN

     - Source=Internal

     - Destination=Preferred WAN

     - NAT=Enable

 

Kindly advise above configuration is correct or wrong. If additional configuration is needed, please guide me on this.

 

Thanks much !!

3 REPLIES 3
ede_pfau
SuperUser
SuperUser

hi,

 

this is mainly a routing problem. There's one (1) and only one default route to unknown hosts on the 'net per system/FGT so you'll have difficulties with LLB alone.

Suggestion: create one VDOM per department, administer them from the 'root' VDOM. This way, each dept. will have it's own firewall, admins, users, policies, routes etc. etc.

Most FGTs feature 10 VDOMs for free, the bigger ones can be expanded up to 500 VDOMs.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
cstan1989

Ok, let me try it..

Thanks lot.

MikePruett

You can also just make sure each department is on a different subnet and do policy routes for specific departments to go out a certain pipe.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Labels
Top Kudoed Authors