Topic Thread

Next Generation Firewall (NGFW)

 View Only
Expand all | Collapse all

DMZ set up and Forigate 200D

  • 1.  DMZ set up and Forigate 200D

    Posted 10-27-2018 13:42
    I am new to Fortigates and trying to understand setting up a DMZ. The first question relates to the physical connections. Do I need an actual physical connection to the DMZ port from the web server or can any of the fortigate lan based ports be used? Second question, what needs to be done to set up the DMZ for virtual servers set up on esxi hosts? We use Vsphere 6.7. I have found directions on setting up the fortigate to use DMZ, my challenge is the physical connection and how this would be set up. Thanks

    Network Administrator

  • 2.  RE: DMZ set up and Forigate 200D

    Posted 10-29-2018 06:43
    The DMZ from the firewall perspective can be any dedicated port you configure with the IP range for your DMZ, then the firewall rules for your DMZ to and from any other interfaces. At that point you have a physical connection you have to connect into a switch port or possibly direct to a server DMZ interface but most times you will have  switch connected into your virtual infrastructure then you connect your DMZ port into that.    On the virtual side you need to configure your setup to get the DMZ server traffic into the same VLAN you connected your firewall to.

    Peter [LastName] [Designation]
    Enterprise Engineer, Networking
    [City] [State]

  • 3.  RE: DMZ set up and Forigate 200D

    Posted 10-29-2018 10:24
    Chris, does Peter's response answer your question? If so, please mark it as a "Best Answer"...