If you are editing the configuration for a physical interface, you cannot set the type. Since Debbie dissected all questions, I have only comment for the design. Syntax config system It actually depends on the FortiOS version: after 4.0 MR3 Patch3 (so, with TL;DR: no you do not need a separate FortiGate to get to the HA management interfaces, but yes you technically need a gateway (another router like a second FortiGate, or the FortiGate itself in a weird loop) if you want to use the HA management interfaces for out-of-band (as in, separate subnet) access, Created on You can create a set of CLI commands to perform an operation, and a separate set to undo the operation. The following example configures port1 (the management interface): allowaccess : https ping ssh snmp http telnet, FortiADC-VM (port1) # set ip 192.0.2.5/24. In response to Matthijs. So to get the mgmt working, the "gateway" in HA mgmt config seems to be not necessary (unusable for that purpose). Created on Created on Specify a space-separated list of the following options: Secondary IP addresses can be used when you deploy the system so that it belongs to multiple logical subnets. Created on 07-01-2022 The addendum part is closer because then the same FGT routes traffic to the separate mgmt network (10.0.0.0/24). Disconnect after idle timeout in seconds. Learn how your comment data is processed. The NTP server must be reachable from the FortiSwitch unit. What is a Chief Information Security Officer? 07-04-2022 Edited on So you are saying you don't have any L3 devices other than those FGTs to route 10.0.0.100/29 and .101&.102 for the first cluster's and .103&.104 for the second cluster's MGMT interfaces? Before you begin: You must have read-write permission for system settings. NOTE: LAG is supported on all FortiSwitch models and on FortiGate models FGT-100D and above. Usually the gateway should be in the same subnet, not in some other. 3. set mode line For each address, specify an IP address using the CIDR-formatted subnet mask, separated by a forward slash ( / ), such as 192.0.2.5/24. I have to think about it, what would it mean in our environment to use that routing and what else needs to be configured then. , Created on If necessary, you can set the MAC address. That is very important to have such to see exactly what happens with booting one of the members. 07-04-2022 Allow inbound service traffic. The do and undo command combination is sometimes referred to as Flex-CLI. HTTPEnables connections to the web UI. We and our partners store and/or access information on a device, To get this info I needed to do an Ifconfig from the Fortigate. WebConfigure interfaces. Basic Fortigate configuration with CLI commands. The valid range is between 1 and 4094. FortiNAC does not detect errors in the structure of the command set being applied on the device. I can't believe that I shold have another (small) FGT for that which operates as the gateway to that mgmt network. Of course. This modifies the network devices behavior as long as those commands are in force. Fortinet recommends using the FortiGate GUI because the CLI procedures are more complex (and therefore more prone to error). If the network has a wide geographic distribution, some features, such as software downloads, might operate slowly. Webconfig system interface Use this command to configure network interfaces. If applicable, select the virtual domain to which the configuration applies. Set the IP address and netmask of the LAN interface: config system interface edit