FortiGate Firewall Policy Routing configuration for dual-link visits

Source: Internet
Author: User

Scenario Description:

1. Dual-link telecommunications links, mainly telecommunications (default route), Unicom supplemented

2. Internal part server requires external access, NAT to Telecom line

3. Requires that some users of the intranet will be able to access the internal server via the NAT Telecom public IP network (assuming

172.16.0.0/24)

4. Suppose that the network segment to be dispatched now is 172.16.100.0/22


This is the time to write a policy route:

routing, static and Policy Routing->create_new:

650) this.width=650; "title=" 1.png "style=" HEIGHT:323PX;WIDTH:584PX; "alt=" Wkiom1bfiwvxnrumaabs_gxctdg441.png "src= "Http://s1.51cto.com/wyfs02/M01/7B/05/wKiom1bFIWvxnruMAABs_gXctdg441.png" width= "844" height= "414"/>


After creating the above policy route, we went to test to find that 172.16.100.0/22 has been dispatched to the Unicom line,

However, a new problem has been created, and the 100.0/22 network segment cannot access the NAT telecom public network IP.

After several attempts, the following methods are finally implemented:

    1. Also create a policy route, as follows

      Incoming interface: Select Firewall Intranet Port

      Destination Address: Enter the server network segment

      Outgoing interface: Select Firewall intranet port 650) this.width=650; "title=" 2.png "style=" Height:293px;width:532px;float:none; "src="/HTTP/ S1.51cto.com/wyfs02/m00/7b/05/wkiom1bfi8sxsyuwaabo_lqussq605.png "width=" 722 "height=" 411 "alt=" Wkiom1bfi8sxsyuwaabo_lqussq605.png "/>

2. Create a firewall policy, the policy inflow interface must select any interface.

650) this.width=650; "title=" 3.png "style=" Height:273px;width:535px;float:none; "src=" http://s1.51cto.com/wyfs02/ M00/7b/05/wkiol1bfjcrc8fg-aaayxfpy7pg544.png "width=" 713 "height=" 307 "alt=" Wkiol1bfjcrc8fg-aaayxfpy7pg544.png "/ >


Through the above configuration, we find that the link exchange can be realized.

This article is from the "Stenning Technology blog" blog, make sure to keep this source http://magic3.blog.51cto.com/1146917/1742892

FortiGate Firewall Policy Routing configuration for dual-link visits

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.