12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Interface<br />

System Network<br />

4 Set the MTU size.<br />

If you select an MTU size larger than your <strong>FortiGate</strong> unit supports, an error<br />

message will indicate this. In this situation, try a smaller MTU size until the value is<br />

supported. Supported maximums are 16110, 9000, and 1500.<br />

Note: If you change the MTU, you need to reboot the <strong>FortiGate</strong> unit to update the MTU<br />

value of VLAN subinterfaces on the modified interface.<br />

Note: In Transparent mode, if you change the MTU of an interface, you must change the<br />

MTU of all interfaces to match the new MTU.<br />

Traffic logging for an interface<br />

You can enable traffic logging for any interface. See “Traffic log” on page 481 for<br />

more information.<br />

Secondary IP Addresses<br />

An interface can be assigned more than one IP address. You can create and apply<br />

separate firewall policies for each IP address on an interface. You can also<br />

forward traffic and use RIP or OSPF routing with secondary IP addresses.<br />

There can be up to 32 secondary IP addresses per interface. Primary and<br />

secondary IP addresses can share the same ping generator.<br />

The following restrictions must be in place before you are able to assign a<br />

secondary IP address.<br />

• A primary IP address must be assigned to the interface first.<br />

• The interface must use manual addressing mode.<br />

• By default, IP addresses cannot be part of the same subnet. To allow interface<br />

subnet overlap use the CLI <strong>com</strong>mand:<br />

config system global<br />

(global)# set allow-interface-subnet-overlap enable<br />

(global)#end<br />

Secondary IP addresses cannot terminate a VPN tunnel.<br />

You can use the CLI <strong>com</strong>mand config system interface to add a<br />

secondary IP address to an interface. For more information, see config<br />

secondaryip under system interface in the <strong>FortiGate</strong> CLI Reference.<br />

Figure 46: Adding Secondary IP Addresses<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

96 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!