Planning The Configuration; Nat/Route Mode - Fortinet FortiSwitch-5203B Manual

Table of Contents

Advertisement

Planning the configuration

Planning the configuration

NAT/Route mode

26
Register and apply licenses to the FortiSwitch-5203Bs and to the workers. This includes
Support licensing, FortiGuard licensing, FortiCloud activation, FortiClient, and FortiToken
licensing, and entering a license key if you purchased more than 10 Virtual Domains
(VDOMS).
All the boards in the cluster must have the same level of licensing. For example, if you
purchase FortiGuard services for each of the workers in the cluster you must purchase
the same FortiGuard services for the FortiSwitch-5203Bs in the cluster. Also, if you
purchase VDOM licenses to increase the number of VDOMs available on the workers you
must also purchase the same VDOM licenses for the FortiSwitch-5203Bs in the cluster.
Before beginning to configure your FortiSwitch-5203B, you need to plan how to integrate
the content cluster into your network. Your configuration plan depends on the operating
mode that you select: NAT/Route mode (the default) or Transparent mode.
In NAT/Route mode, the FortiSwitch-5203B content cluster is visible to the networks that
it is connected to. Each FortiSwitch-5203B interface connected to a network must be
configured with an IP address that is valid for that network. In many configurations, in
NAT/Route mode all of the FortiSwitch-5203B interfaces are on different networks, and
each network is on a separate subnet.
You would typically use NAT/Route mode when the FortiSwitch-5203B content cluster is
deployed as a gateway between private and public networks. In the default NAT/Route
mode configuration, the FortiSwitch-5203B content cluster functions as a firewall.
Firewall policies control communications through the cluster. No traffic can pass through
the cluster until you add firewall policies.
In NAT/Route mode, firewall policies can operate in NAT mode or in Route mode. In NAT
mode, the FortiGate firewall performs network address translation before IP packets are
sent to the destination network. In Route mode, no translation takes place.
Configuring Content Clustering
FortiSwitch-5203B Security System Guide
01-520-145204-20151108
http://docs.fortinet.com/

Advertisement

Table of Contents
loading

Table of Contents