Question

FortiGate 60 with two PPPoE connections

Asked by: I_play_with_DNA

I have a Fortigate 60 firewall.  Both WAN ports are connected to the same DSL modem via an ethernet switch.  Each WAN port is configured to use different PPPoE user/names and passwords and, when logged in, each WAN port is assigned a different static IP.  We use NAT/port forwarding to machines on our LAN.

What I would like to get set up is a system where all traffic on our network goes out through WAN1, except for traffic to/from one web server on our network, which I would like to go through WAN2.  I'm doing this because there is already a web server on our network accessible through WAN1 and I need the second to also be accessible from the web.

Everything works fine when WAN1 is PPPoE logged in, but as soon as WAN2 is PPPoE conencted, no traffic seems to flow in or out of our network via either WAN interface; everything is blocked.  If I disconnect WAN2, everything goes back to normal.

Can someone please let me know what I might be doing wrong here?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2008-11-13 at 02:10:20ID23901195
Topics

Networking Hardware Firewalls

,

DSL Lines / Cable Internet

Participating Experts
1
Points
500
Comments
4

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. PPPoE over Ethernet over L2TP
    Hi all, Is the following configuration can work ? 1. End user with PPPoE clietn and Ethernet connection to HUb 2. Multiple PPPoE session connected to a Router via a shared Ethernet 3. Router connected to Remote BRAS via a IP Network (either a multi-hop network or IP VPN/L2T...
  2. PPPoE over Ethernet over IP Network
    Hi all, Is the following configuration feasible? 1. End user with PPPoE clietn and Ethernet connection to HUb 2. Multiple PPPoE session connected to a Router via a shared Ethernet 3. Router connected to Remote BRAS via a IP Network (either a multi-hop network or IP VPN/L2TP...
  3. Cisco 827 PPPoE
    I have come across a Cisco 827 router, which I believe is currently configured for PPPoA. They are changing carriers to a PPPoE dsl carrier. At the back of the device, I see that it's an ADSL interface, but the name of the interface is ATM0. Does this sound like a decent c...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: yuriskPosted on 2008-11-13 at 23:36:34ID: 22957798

There are few issues to be addressed:
1) Default Gateway - when connected by PPPOE FG dynamically installs route
0.0.0.0 through the connected interface. So if, after being connected by 2 dialers
you will go to Router -> Monitor you'll see there 2 default routes to 0.0.0.0 and this
blocks the traffic as FG doesnt know which one to use.
2) TO fix above you will need to chnage Distance  in NEtwork- Interface ->WAN2
Put distance of say 10. This will prevent anyone using WAN2 by default

3) To pass web traffic from server  through WAN2 only  implement Policy Routing. Go to Router-> Static->Policy  Route -> Create New , in the Parameters put the following:

Protocol   0
Incoming Interface :  <interface where the web server is>
Source address / mask: <IP of the web server in LAN>
Destination address / mask: 0.0.0.0/0.0.0.0
Destination Ports:  1   65535
Outgoing interface:   wan2
Gateway Address: < Best to put next hop for the WAN2 link if known,if not known 0.0.0.0 >

4) To route all incoming web server traffic through WAN2, create Virtual IP
with IP of the PPPOE WAN2 and interface/IP of webserver in parameters. Also create rule
incoming from outside port 80 , destination Virtual IP just created

 

by: I_play_with_DNAPosted on 2008-11-14 at 01:22:12ID: 22958145

@yurisk

Thanks for the reply.  I will try this Friday evening, because I can't muck with the firewall during business hours.

 

by: I_play_with_DNAPosted on 2008-11-14 at 14:32:32ID: 22964289

@yurisk

Ok, I've tried out what you suggested.  Here are the results:

1 & 2)  I changed the distance on the WAN2 interface to 10 as you said.  Once I did this, it stopped the extra route from being entered in the routing table and solved my problem of traffic blockage when both WAN ports are connected.

3 & 4)  I implemented a Policy Route and Virtual IP/Firewall Policy as you suggested.  After I did this, I wanted to check to see if all traffic from the new web server was going out through WAN2, so I opened a web browser and went to www.whatismyip.com, but the site reported the IP of WAN1, not WAN2.  Am I wrong in thinking that if all traffic to/from the web server is going out through WAN2, that the web site should have reported the IP of WAN2?

I've included screen shots of the policy route and virtual IP/firewall policy below so you can see what I have configured.  Ideally what I would like to happen is this:

All traffic from web server that is destined for machines NOT on our LAN goes out through WAN2.  All incoming traffic destined for web server comes in through WAN2.  I don't want web server to be able to communicate through WAN1 at all, either inbound or outbound.  Internal IP of the web server is 192.168.1.16

 

by: yuriskPosted on 2008-11-15 at 00:17:24ID: 22966211

If it doesnt install default route through WAN2 at all after increasing the Distance,
then return the Distance parameter of the WAN2 to the default route so that both
default routes are installed again , check in ROuter->Monitor.
Then in Policy Route change subnet mask to that  of 32 bits: 192.168.1.16/255.255.255.255.
I think that would be enough - if not, create another  Route Policy thta lists whole LAN
adn throws it to the WAN1 interface.

VIrtual IP is right, and the check you do - entering whatismyip is the one to prove that it is working.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...