Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rchyka
New Contributor

Fortigate 60F - Connect our Internal Switch

Hello - I am new to FortiGate.  Our old admin bought a 60F and then left the company so I am stuck trying to get it online.  We are migrating form a Cisco ASA that has reached end of life.   I setup the ASA years ago and now I am trying to figure out the Fortinet so excuse my elementary questions.

 

With our ASA I would connect a port form one of our Cisco switches to Port 1 on the ASA and assign it an IP address as the internal interface.  I did see that Fortinet comes configured with all the internal switchports configured as 1 so I removed all of the ports except for Port 1 which I am managing the switch through.  It also has DHCP server turned on that port but our DHCP is handled internally on a Windows Server so I am going to turn that off and I shouldnt lose management capabilities still using port 1 to my laptop.

 

TO connect our internal network to the Fortigate should I configure port 2 as a hardware switch and assign it an internal IP address like Cisco does?  After that I will have to turn the port on because it is disabled after I removed it from the group.

 

I think I am on the right track but want to verify before I go further into the device with more advanced configs.

 

Thank you!

 

 

1 REPLY 1
sw2090
Honored Contributor

hm I here remove the factory default switch completely and use the ports on their own then.

I usually use port1/internal1 as internal interface. FGT has an IP on that and the port connects to one of our core switches. All required vlans on the FGT are then tied to that port and the uplink port of the switch that connects to the FGT is tagged in all vlans and so are all other uplinks.

 

That just requires policies on the FGT then to allow traffic (and [reverse] static routing if it goes to outside the FGT (like traffic from/to HQ via IPSec).

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors