12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Router Static<br />

Static Route<br />

• Device: Name of the interface connected to network 192.168.10.0/24<br />

(for example, external).<br />

• Distance: 10<br />

The Gateway setting specifies the IP address of the next hop router interface to<br />

the <strong>FortiGate</strong> external interface. The interface behind the router (192.168.10.1) is<br />

the default gateway for <strong>FortiGate</strong>_1.<br />

In some cases, there may be routers behind the <strong>FortiGate</strong> unit. If the destination<br />

IP address of a packet is not on the local network but is on a network behind one<br />

of those routers, the <strong>FortiGate</strong> routing table must include a static route to that<br />

network. For example, in Figure 147, the <strong>FortiGate</strong> unit must be configured with<br />

static routes to interfaces 192.168.10.1 and 192.168.11.1 in order to forward<br />

packets to Network_1 and Network_2 respectively.<br />

Figure 147:Destinations on networks behind internal routers<br />

Internet<br />

<strong>FortiGate</strong>_1<br />

internal<br />

dmz<br />

Router_1 192.168.10.1<br />

192.168.11.1<br />

Router_2<br />

Network_1<br />

192.168.20.0/24<br />

Network_2<br />

192.168.30.0/24<br />

To route packets from Network_1 to Network_2, Router_1 must be configured to<br />

use the <strong>FortiGate</strong> internal interface as its default gateway. On the <strong>FortiGate</strong> unit,<br />

you would create a new static route with these settings:<br />

Destination IP/mask: 192.168.30.0/24<br />

Gateway: 192.168.11.1<br />

Device: dmz<br />

Distance: 10<br />

To route packets from Network_2 to Network_1, Router_2 must be configured to<br />

use the <strong>FortiGate</strong> dmz interface as its default gateway. On the <strong>FortiGate</strong> unit, you<br />

would create a new static route with these settings:<br />

Destination IP/mask: 192.168.20.0/24<br />

Gateway: 192.168.10.1<br />

Device: internal<br />

Distance: 10<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 237

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!