Link to home
Start Free TrialLog in
Avatar of Anonymous KH
Anonymous KHFlag for Singapore

asked on

Fortigate 90D setup

Dear Experts,

I have finish duplicating the policies from the Netscreen-25 to the Fortigate 90D.

My boss told me that I cannot have duplicate interface name but can have duplicate zone name.
WLAN.JPG
WLAN-error.JPG
Netscreen-Zone.png
SOLUTION
Avatar of gheist
gheist
Flag of Belgium image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Anonymous KH

ASKER

Hi! ghesit,

So am I doing it wrongly?
No idea. From your bare screenshots nobody can tell.
I connected my laptop to the fortigate to test and I have an IP address that is following what was configured on the fortigate, but I cannot go to the internet.
network ports are down?
Can elaborate more on this I am still very new on IT infrastructure?
It shows icons as if network cables are unplugged or interfaces are not brought up.
Can you ping fortigate?
SOLUTION
Avatar of myramu
myramu

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
myramu,

I have done a reverse setup.

I have removed all the policies, leaving behind the objects and services.

With the setup of three VDOMs in the fortigate.

Should the next step be to setup the zones or zone mapping, am I right?

User generated image
Avatar of myramu
myramu

Creating zones is really not requited in your setup because u have 1 wan and 1 lan as per the attached screenshot. Zone is required when you have 2 LAN subnets and you want to create identical policies.

Good Luck!
Hi! myramu,

my office is using 192.168.168.X and we have to connect to our icebox which is located at the data centre where the subnet is 192.168.88.X. Is this 2 LAN subnets?
When you create Zone, it is not possible use the zone member interfaces separately to create policies.  Make sure that you need to allow similar services for both the LANs, then only create zone.

Good Luck!
I am not sure if I am correct, because the zone is to assign like DMZ, Trust, Untrust, VOIP, etc...
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Two days ago, my office Netscreen 25 firewall's LED lights just stayed on throughout. My boss decided to use the Fortigate 90D firewall. I told him that I was not able to create the zones which was where I got stuck. In the end, he took over and set everything the way it was like the Netscreen 25 firewall.