Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MarcusI
New Contributor

ISP and ports LAN/WAN

Good afternoon, Well, I'm here for a couple of consultations: 1) In the company we have 2 ISPs, let's say A and B and we want our neighbors to only go through ISP B. They arrive through a cable from a direct switch to a LAN port to our fortigate. What would be the best way to do what was proposed? and 2) By doing some tests we have separated a port from the LAN and we have converted it into WAN. Is there a way to remove it and return it to the LAN? because if there is, we can not find it. Greetings and thanks in advance.

3 REPLIES 3
sw2090
Honored Contributor

1) create a policy that allows traffic from your neighbour to the internet only through ISP B. Or maybe use SDWAN and do IP based blancing (but I am not sure if you can split upon source ip in here).

 

2) you cannot convert an interface. You can only change it's role to WAN. If you want to revert that just change the role back to LAN :)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
ede_pfau

1) look up "Policy routing". This is a route which is not (only) determined by the destination, but by the source subnet. All traffic from your neighbor's subnet will then be directed to the port serviced by ISP B.

A simple policy won't do but is (of course) additionally required.

 

2) "All Ports Are Created Equal". There is no difference between ports except for their label.

There is only one exception (there's always one): management ports are non-routing and should not be used for production traffic.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
mike_dp

use SD-WAN with FortiOS of 6.0.X and set a SD-WAN rule with their source ip range and the ISP B interface as a destination (like a policy route). That's pretty much what we do to separate the public wifi of the regular LAN network. SD-WAN will clearly simplify your Internet/VPN IPSec policies if you include multiple interfaces in it.

Fortigate : 80E, 80F, 100E, 200F, 300E : 6.4.6

FortiAnalyzer, ForticlientEMS

Fortigate : 80E, 80F, 100E, 200F, 300E : 6.4.6 FortiAnalyzer, ForticlientEMS
Labels
Top Kudoed Authors