Fortinet black logo

Administration Guide

FortiExtender

FortiExtender

Two configuration modes are available on FortiGate for FortiExtender integration: WAN extension mode and LAN extension mode.

Tooltip

For information about configuring FortiExtender, see the FortiExtender Admin Guide (FGT-Managed) and Admin Guide (Standalone).

WAN extension mode

In WAN extension mode, the FortiExtender works as an extended WAN interface in IP pass-through mode. The FortiGate manages FortiExtender over the CAPWAP protocol in IP pass-through mode, and is integrated into FortiOS as a manageable interface.

Sample configurations in WAN extension mode could include connecting a FortiExtender to two FortiGates in HA active-passive mode, or connecting two FortiExtenders to two FortiGates in HA active-active mode to provide dual active redundancy for wireless WAN access.

For more information, see FortiExtender and FortiGate integration in the FortiExtender (Managed) Administration Guide.

LAN extension mode

The LAN extension configuration mode allows FortiExtender to provide remote thin edge connectivity back to the FortiGate over a backhaul connection. A FortiExtender deployed at a remote location will discover the FortiGate access controller (AC) and form an IPsec tunnel (or multiple tunnels when multiple links exist on the FortiExtender) back to the FortiGate. A VXLAN is established over the IPsec tunnels to create an L2 network between the FortiGate and the network behind the remote FortiExtender.

For more information, see FortiExtender as FortiGate LAN extension in the FortiExtender (Managed) Administration Guide.

Maximum FortiExtender devices supported per mode

FortiOS supports a maximum number of FortiExtender devices in WAN or LAN extension mode:

FortiGate Models

WAN

LAN

FortiGate 40F series and its variants, FortiGate VM01

2

0

FortiGate 60F, 70F, 80F series and their variants, FortiGate VM02

2

16

FortiGate 100E to 200F series and their variants

2

16

FortiGate 400F to 900G series and their variants, FortiGate VM04

2

32

FortiGate 1000D to 2600F series and their variants, FortiGate VM08

2

256

FortiGate 3000D and higher, FortiGate VM16 and higher

2

1024

FortiExtender

FortiExtender

Two configuration modes are available on FortiGate for FortiExtender integration: WAN extension mode and LAN extension mode.

Tooltip

For information about configuring FortiExtender, see the FortiExtender Admin Guide (FGT-Managed) and Admin Guide (Standalone).

WAN extension mode

In WAN extension mode, the FortiExtender works as an extended WAN interface in IP pass-through mode. The FortiGate manages FortiExtender over the CAPWAP protocol in IP pass-through mode, and is integrated into FortiOS as a manageable interface.

Sample configurations in WAN extension mode could include connecting a FortiExtender to two FortiGates in HA active-passive mode, or connecting two FortiExtenders to two FortiGates in HA active-active mode to provide dual active redundancy for wireless WAN access.

For more information, see FortiExtender and FortiGate integration in the FortiExtender (Managed) Administration Guide.

LAN extension mode

The LAN extension configuration mode allows FortiExtender to provide remote thin edge connectivity back to the FortiGate over a backhaul connection. A FortiExtender deployed at a remote location will discover the FortiGate access controller (AC) and form an IPsec tunnel (or multiple tunnels when multiple links exist on the FortiExtender) back to the FortiGate. A VXLAN is established over the IPsec tunnels to create an L2 network between the FortiGate and the network behind the remote FortiExtender.

For more information, see FortiExtender as FortiGate LAN extension in the FortiExtender (Managed) Administration Guide.

Maximum FortiExtender devices supported per mode

FortiOS supports a maximum number of FortiExtender devices in WAN or LAN extension mode:

FortiGate Models

WAN

LAN

FortiGate 40F series and its variants, FortiGate VM01

2

0

FortiGate 60F, 70F, 80F series and their variants, FortiGate VM02

2

16

FortiGate 100E to 200F series and their variants

2

16

FortiGate 400F to 900G series and their variants, FortiGate VM04

2

32

FortiGate 1000D to 2600F series and their variants, FortiGate VM08

2

256

FortiGate 3000D and higher, FortiGate VM16 and higher

2

1024