AnsweredHot!Connect Fortigate 60E to CANTV Metro Ethernet

Author
DearkMasterMU
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2021/03/11 04:49:57
  • Status: offline
2021/03/11 05:27:25 (permalink)
0

Connect Fortigate 60E to CANTV Metro Ethernet

Hi
We have a Venezuela CANTV Metro Ethernet link and we need to connect to Fortigate 60E in port 7 (WAN1 & 2 are in use in a SD-WAN and we need to include this link)
 
We received from CANTV the follow parameters
VLAN:                   118
CANTV WAN IP:     190.202.4.9
Customer WAN IP: 190.202.4.10
WAN Mask:            255.255.255.252
LAN IP:                 201.249.206.128 
IP Available:          201.249.206.129 to 134 (135 is for broadcast)
LAN Mask:            255.255.255.248
 
Someone can help us? We will appreciate a lot...
 
Regard

Miguel Ustariz
#1
sw2090
Expert Member
  • Total Posts : 923
  • Scores: 76
  • Reward points: 0
  • Joined: 2017/06/14 01:27:25
  • Location: Regensburg
  • Status: offline
Re: Connect Fortigate 60E to CANTV Metro Ethernet 2021/03/11 07:55:31 (permalink) ☄ Helpfulby DearkMasterMU 2021/03/11 08:10:40
5 (1)
I can't say for sure.
 
I just guess:
 
CANTV WAN IP:     190.202.4.9
Customer WAN IP: 190.202.4.10
 
this is PTP between CANTV and your Model or whatever is connected to the port on FGT.
 
LAN IP:                 201.249.206.128 
IP Available:          201.249.206.129 to 134 (135 is for broadcast)
LAN Mask:            255.255.255.248
 
this is what your port needs.
 
Accoarding to the LAN Mask that's a /29 subnet. That means:
201.249.206.128 is network address (cannot be given to any interface)
201.249.206.129-134 are 6 usable IP Addresses you can put up on your interface.
201.249.206.135 is broadcast address (cannot be given to any interface)
 
so just the default gw is unclear. I'd try the CANTV WAN IP as gateway.
 
#2
DearkMasterMU
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2021/03/11 04:49:57
  • Status: offline
Re: Connect Fortigate 60E to CANTV Metro Ethernet 2021/03/11 08:10:26 (permalink)
0
Thanks a lot
All your guess are right. My problem: how we configure this in our Fortigate, port 7?
Regards

Miguel Ustariz
#3
sw2090
Expert Member
  • Total Posts : 923
  • Scores: 76
  • Reward points: 0
  • Joined: 2017/06/14 01:27:25
  • Location: Regensburg
  • Status: offline
Re: Connect Fortigate 60E to CANTV Metro Ethernet 2021/03/11 23:09:04 (permalink) ☼ Best Answerby DearkMasterMU 2021/03/12 03:47:44
5 (2)
set the port to static ip configuration.
Give it one out of the usable ips (or annother as secondary ip if you want/need it).
Add the port to sd-wan and sd-wan health check and enter the default gateway there.
 
#4
DearkMasterMU
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2021/03/11 04:49:57
  • Status: offline
Re: Connect Fortigate 60E to CANTV Metro Ethernet 2021/03/12 03:48:50 (permalink)
0
Thank a lot. I will configure the port as you tell us.
Regards

Miguel Ustariz
#5
PerthNSE
New Member
  • Total Posts : 7
  • Scores: -1
  • Reward points: 0
  • Joined: 2020/07/28 21:05:21
  • Status: offline
Re: Connect Fortigate 60E to CANTV Metro Ethernet 2021/03/12 06:23:33 (permalink) ☄ Helpfulby DearkMasterMU 2021/03/12 09:22:58
4 (1)
Just adding a thought here - 
 
You may need to create a VLAN interface (VLANID 118) on Port 7 to configure the PTP WAN link on.
 
Also - the "LAN" Subnet IP's are publicly routable addresses, which is strange to me. I would likely configure them as VIP's unless you need to have some devices that cannot be NAT'd.
 
Alternatively you can allocate them to a 'DMZ' VLAN/Interface and use 201.249.206.129 as the FortiGate IP on that network, which will also serve at the gateway IP.
#6
DearkMasterMU
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2021/03/11 04:49:57
  • Status: offline
Re: Connect Fortigate 60E to CANTV Metro Ethernet 2021/03/12 09:26:39 (permalink)
0
Hi and thank Perth
How we can configure the VLAN and which IP need to use?
Regards 

Miguel Ustariz
#7
Jump to:
© 2021 APG vNext Commercial Version 5.5