Configuring a /30 IP block and a /26 IP block

Posted on 2016-08-28
Last Modified: 2016-08-29
My ISP gave me a /30 address that is to be used to route my /26 block of IP addresses.

/30 block ISP side my side (Fortigate firewall)

/26 block of addresses /26

Internal network

My network is able to browse the internet just fine, with all internet traffic going through the gateway.  How do I setup my network to utilize the /26 block of addresses?

Thank you for any suggestions.
Question by:lawemcsd
LVL 37

Expert Comment

ID: 41773635
it depends on the devices before the FortiGate firewall as well as the FortiGate device itself.

1. please advise your the model of your FortiGate device.

2. please advise if there is any device to use the /26 IPs before the FortiGate firewall, or everything is behind or protected by the FortiGate firewall?
LVL 27

Expert Comment

by:Predrag Jovic
ID: 41773652
How do I setup my network to utilize the /26 block of addresses?
Typically you should create Nat pool for your IP address range (/26 block) and then just create NAT translation rules that your private IP address range use that nat pool, so traffic gets natted with that IP address range. Default route is still the same - next hop is The rest is up to ISP - they need to configure route(s) that will  point to your WAN ip address as next hop to reach your /26 block.

Author Comment

ID: 41773982
Hi, Thanks for the responses.

I'm using a Fortigate 800c. And the /26 address would all be behind the firewall.  

Do I need to establish a port to  act as the gateway for  What's ideal?

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

LVL 27

Assisted Solution

by:Predrag Jovic
Predrag Jovic earned 250 total points
ID: 41774244
/26 address would all be behind the firewall
In that case you don't NAT traffic for those, just create routes (if needed) and that's it (sure ther should be some gateways somewhere :) ). However, not sure for configuration details on Fortigate.
LVL 69

Accepted Solution

Qlemo earned 250 total points
ID: 41774645
It depends on what you want to do, but you
either use a DMZ for those /26 addresses, just routing them thru and allowing "interesting" or all traffic
or create port-forwarding for /26 addresses on FortiGate (with appropriate NAT policies allowing traffic) to (private) LAN IPs.

The DMZ has the advantage that traffic is kept separate for public IPs and LAN, and you are able to define granular access rules (policies) for DMZ <=> LAN traffic. DMZ is more secure.

Author Closing Comment

ID: 41775714
Thanks folks!

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
What type of checksum is used for Cisco/Linksys RV router configurations? 18 76
Wireless network monitoring 8 64
Open a port on Cisco Router 1941 23 40
slow vpn connection 9 66
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question