54
Fortinet Inc.
Configuration example: Multiple connections to the Internet
NAT/Route mode installation
Load sharing
You can also configure destination routing to direct traffic through both gateways at
the same time. If users on your internal network connect to the networks of ISP1 and
ISP2, you can add routes for each of these destinations. Each route can include a
backup destination to the network of the other ISP.
The first route directs all traffic destined for the 100.100.100.0 network to gateway 1
with the IP address 1.1.1.1. If this router is down, traffic destined for the 100.100.100.0
network is re-directed to gateway 2 with the IP address 2.2.2.1.
Load sharing and primary and secondary connections
You can combine these routes into a more complete multiple internet connection
configuration. In the topology shown in
Figure 7 on page 52
, users on the Internal
network would connect to the Internet to access web pages and other Internet
resources. However, they may also connect to services, such as email, provided by
their ISPs. You can combine the routes described in the previous examples to provide
users with a primary and backup connection to the Internet, while at the same time
routing traffic to each ISP network as required.
The routing described below allows a user on the internal network to connect to the
Internet through gateway 1 and ISP1. At the same time, this user can also connect
through the DMZ interface to gateway 2 to access a mail server maintained by ISP2.
Adding the routes using the web-based manager
1
Go to
System > Network > Routing Table
.
2
Select New to add the default route for primary and backup links to the Internet.
• Destination IP: 0.0.0.0
• Mask: 0.0.0.0
• Gateway #1: 1.1.1.1
• Gateway #2: 2.2.2.1
• Device #1: wan1
• Device #2: wan2
• Select OK.
Table 15: Route for primary and backup links
Destination IP‘ Mask
Gateway #1
Device #1
Gateway #2
Device #2
0.0.0.0
0.0.0.0
1.1.1.1
wan1
2.2.2.1
wan2
Table 16: Load sharing routes
Destination IP‘ Mask
Gateway #1
Device #1
Gateway #2
Device #2
100.100.100.0
255.255.255.0
1.1.1.1
wan1
2.2.2.1
wan2
200.200.200.0
255.255.255.0
2.2.2.1
wan2
1.1.1.1
wan1
Содержание FortiGate 60R
Страница 12: ...Contents 12 Fortinet Inc...
Страница 26: ...26 Fortinet Inc Customer service and technical support Introduction...
Страница 42: ...42 Fortinet Inc Next steps Getting started...
Страница 106: ...106 Fortinet Inc Registering a FortiGate unit after an RMA Virus and attack definitions updates and registration...
Страница 138: ...138 Fortinet Inc Customizing replacement messages System configuration...
Страница 228: ...228 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS...
Страница 242: ...242 Fortinet Inc Exempt URL list Web filtering...
Страница 256: ...256 Fortinet Inc Configuring alert email Logging and reporting...
Страница 260: ...260 Fortinet Inc Glossary...
Страница 270: ...270 Fortinet Inc Index...