Secondary Ip Addresses - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

Configuring interfaces

Secondary IP Addresses

196
Note: In Transparent mode, if you change the MTU of an interface, you must change the
MTU of all interfaces on the FortiGate unit to match the new MTU.
See also
An interface can be assigned more than one IP address. You can create and apply
separate firewall policies for each IP address on an interface. You can also forward traffic
and use RIP or OSPF routing with secondary IP addresses.
There can be up to 32 secondary IP addresses per interface including primary, secondary,
and any other IP addresses assigned to the interface. Primary and secondary IP
addresses can share the same ping generator.
The following restrictions must be in place before you are able to assign a secondary IP
address:
A primary IP address must be assigned to the interface.
The interface must use manual addressing mode.
By default, IP addresses cannot be part of the same subnet. To allow interface subnet
overlap use the CLI command:
config system global
set allow-interface-subnet-overlap enable
end
You can use the CLI command
address to an interface. For more information, see
system interface
in the
Figure 81: Adding Secondary IP Addresses
IP/Netmask
Enter the IP address/subnet mask in the IP/Netmask field.
The Secondary IP address must be on a different subnet than the Primary IP
address.
This field is only available in Manual addressing mode.
Ping Server
To enable dead gateway detection, enter the IP address of the next hop
router on the network connected to the interface and select Enable.
Multiple addresses can share the same ping server.
Administrative
Select the types of administrative access permitted on the secondary IP.
These can be different from the primary address.
Access
HTTPS
Allow secure HTTPS connections to the web-based manager through this
secondary IP.
PING
Allow secondary IP to respond to pings. Use this setting to verify your
installation and for testing.
config system interface
config secondaryip
FortiGate CLI
Reference.
FortiGate Version 4.0 MR1 Administration Guide
System Network
to add a secondary IP
under
01-410-89802-20090903
http://docs.fortinet.com/
Feedback

Advertisement

Table of Contents
loading

Table of Contents