144
01-28007-0144-20041217
Fortinet Inc.
Static
Router
For example, consider
Figure 51
, which shows a FortiGate unit connected to a router.
To ensure that all outbound packets destined to any network beyond the router are
routed to the correct destination, you must edit the default configuration and make the
router the default gateway for the FortiGate unit.
Figure 51: Making a router the default gateway
To route outbound packets from the internal network to destinations that are not on
network 192.168.20.0/24, you would edit the default static route and include the
following settings:
• Destination IP/mask:
0.0.0.0/0.0.0.0
• Gateway:
192.168.10.1
• Device: Name of the interface connected to network 192.168.10.0/24 (e.g.
external
).
• Distance: 10
The Gateway setting specifies the IP address of the next hop router interface to the
FortiGate
external
interface. The interface behind the router (
192.168.10.1
) is
the default gateway for FortiGate_1.
In some cases, there may be routers behind the FortiGate unit. If the destination IP
address of a packet is not on the local network but is on a network behind one of those
routers, the FortiGate routing table must include a static route to that network. For
example, in
Figure 52
, the FortiGate unit must be configured with static routes to
interfaces 192.168.10.1 and 192.168.10.2 in order to forward packets to Network_1
and Network_2 respectively.
Esc
Enter
FortiGate_1
192.168.20.0/24
Internal network
Router
Internet
192.168.10.1
external
Summary of Contents for FortiGate FortiGate-60M
Page 12: ...Contents 12 01 28007 0144 20041217 Fortinet Inc Index 369 ...
Page 44: ...44 01 28007 0144 20041217 Fortinet Inc Changing the FortiGate firmware System status ...
Page 74: ...74 01 28007 0144 20041217 Fortinet Inc FortiGate IPv6 support System network ...
Page 82: ...82 01 28007 0144 20041217 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28007 0144 20041217 Fortinet Inc Access profiles System administration ...
Page 234: ...234 01 28007 0144 20041217 Fortinet Inc Protection profile Firewall ...
Page 246: ...246 01 28007 0144 20041217 Fortinet Inc CLI configuration Users and authentication ...
Page 278: ...278 01 28007 0144 20041217 Fortinet Inc CLI configuration VPN ...
Page 340: ...340 01 28007 0144 20041217 Fortinet Inc Using Perl regular expressions Spam filter ...
Page 358: ...358 01 28007 0144 20041217 Fortinet Inc CLI configuration Log Report ...
Page 376: ...376 01 28007 0144 20041217 Fortinet Inc Index ...