NAT/Route mode installation
Connecting the FortiGate unit to the network(s)
Configuring the networks
40
If you cannot browse to the web site or retrieve/send email from your account,
review the previous steps to ensure all information was entered correctly and try
again.
When you have completed the initial configuration, you can connect the FortiGate
unit between your internal network and the Internet.
To connect the FortiGate unit
1
Connect Port 1to the Internet.
2
Connect Port 2 interface to the hub or switch connected to your internal network.
3
Optionally, connect the other interfaces to networks as required.
You can use a DMZ network to provide access from the Internet to a web server or
other server without installing the servers on your internal network.
Figure 7: FortiGate-3600A NAT/Route mode connections
Internet
If you are running the FortiGate unit in NAT/Route mode, your networks must be
configured to route all Internet traffic to the IP address of the interface where the
networks are connected.
•
For the internal network, change the default gateway address of all computers
and routers connected directly to your internal network to the IP address of the
FortiGate internal interface.
•
For the DMZ network, change the default gateway address of all computers
and routers connected directly to your DMZ network to the IP address of the
FortiGate interface connecting to the DMZ.
FortiGate-3016B, FortiGate-3600A and FortiGate-3810A FortiOS 3.0 MR5 Install Guide
Hub or switch
Port 2
Port 1
Router
Port 3
(or public switch)
Configuring
Internal
network
FortiGate-3600A
Web Server
Mail Server
01-30005-0343-20071113