Configuring the networks
Configuring the networks
34
2
Connect the External interface to the Internet.
Connect to the public switch or router provided by your Internet Service Provider. If
you are a DSL or cable subscriber, connect the External interface to the internal or
LAN connection of your DSL or cable modem.
3
Optionally connect the DMZ/HA interface to the DMZ network.
You can use a DMZ network to provide access from the Internet to a web server or
other server without installing the servers on the internal network.
Figure 9: FortiGate-300 NAT/Route mode connections
Hub or Switch
Esc
FortiGate-300
If you are running the FortiGate unit in NAT/Route mode, your networks must be
configured to route all Internet traffic to the IP address of the FortiGate interface to
which they are connected.
•
For the internal network, change the default gateway address of all computers and
routers connected directly to your internal network to the IP address of the
FortiGate internal interface.
•
For the DMZ network, change the default gateway address of all computers and
routers connected directly to your DMZ network to the IP address of the FortiGate
DMZ interface.
•
For the external network, route all packets to the FortiGate external interface.
Internal Network
Internal
Enter
External
Public Switch
or Router
Internet
01-28004-0021-20040830
NAT/Route mode installation
DMZ Network
DMZ
Hub or Switch
Web Server
Mail Server
Fortinet Inc.