Fortinet Document Library

Version:

Version:


Table of Contents

Admin Guide (Standalone)

Download PDF
Copy Link

IP pass-through mode

In IP pass-through mode, FortiExtender (Standalone) distributes the WAN IP address provided by the NSP to the device behind it.

Enable IP pass-through mode

FortiExtender (Standalone) can be used as a stand-alone device, without integration with FortiGate or FortiExtender (Standalone) Cloud. In this scenario, all configuration is done locally on the FortiExtender (Standalone) device. We call this mode of operation "local" mode.

You can enable IP pass-through in local mode using the following commands:

# config system management

(management)# set discovery-type local

(management) <M># config local

(local)# set mode ip-passthrough

There can be only a single device behind FortiExtender (standalone) when in IP-passthrough mode. That device can be either a router that NAT's the traffic behind or a PC, but it cannot be a switch (L2 or L3) without NAT.

Configure a virtual wire pair

A virtual wire pair configuration is necessary to enable the IP Pass-through forwarding between two ports.

FX212E5919000009 # config system virtual-wire-pair

FX212E5919000009 (virtual-wire-pair) # set lte1-mapping lan

FX212E5919000009 (virtual-wire-pair)# end

IP pass-through mode

In IP pass-through mode, FortiExtender (Standalone) distributes the WAN IP address provided by the NSP to the device behind it.

Enable IP pass-through mode

FortiExtender (Standalone) can be used as a stand-alone device, without integration with FortiGate or FortiExtender (Standalone) Cloud. In this scenario, all configuration is done locally on the FortiExtender (Standalone) device. We call this mode of operation "local" mode.

You can enable IP pass-through in local mode using the following commands:

# config system management

(management)# set discovery-type local

(management) <M># config local

(local)# set mode ip-passthrough

There can be only a single device behind FortiExtender (standalone) when in IP-passthrough mode. That device can be either a router that NAT's the traffic behind or a PC, but it cannot be a switch (L2 or L3) without NAT.

Configure a virtual wire pair

A virtual wire pair configuration is necessary to enable the IP Pass-through forwarding between two ports.

FX212E5919000009 # config system virtual-wire-pair

FX212E5919000009 (virtual-wire-pair) # set lte1-mapping lan

FX212E5919000009 (virtual-wire-pair)# end