System Network Interfaces
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424 137
http://docs.fortinet.com/ • Feedback
config system global
set allow-interface-subnet-overlap enable
end
You can use the CLI command
config system interface to add a secondary IP
address to an interface. For more information, see
config secondaryip under
system interface in the FortiGate CLI Reference.
Figure 65: Adding Secondary IP Addresses
IP/Netmask Enter the IP address/subnet mask in the IP/Netmask field.
The Secondary IP address must be on a different subnet than the Primary IP
address.
This field is only available in Manual addressing mode.
Ping Server To enable dead gateway detection, enter the IP address of the next hop
router on the network connected to the interface and select Enable. See
“Dead gateway detection” on page 146.
Multiple addresses can share the same ping server.
Administrative
Access
Select the types of administrative access permitted on the secondary IP.
These can be different from the primary address.
HTTPS Allow secure HTTPS connections to the web-based manager through this
secondary IP.
PING Allow secondary IP to respond to pings. Use this setting to verify your
installation and for testing.
HTTP Allow HTTP connections to the web-based manager through this secondary
IP. HTTP connections are not secure and can be intercepted by a third party.
SSH Allow SSH connections to the CLI through this secondary IP.
SNMP Allow a remote SNMP manager to request SNMP information by connecting
to this secondary IP. See “Configuring SNMP” on page 186.
TELNET Allow Telnet connections to the CLI through this secondary IP. Telnet
connections are not secure and can be intercepted by a third party.
Add Select Add to add the configured secondary IP address to the secondary IP
table.
Addresses in this table are not added to the interface until you select OK or
Apply.
Secondary IP table A table that displays all the secondary IP addresses that have been added to
this interface.
These addresses are not permanently added to the interface until you select
OK or Apply.
# The identifying number of the secondary IP address.
IP/Netmask The IP address and netmask for the secondary IP.
Ping Server The IP address of the ping server for the address. The ping server can be
shared by multiple addresses.
Enable Indicates if the ping server option is selected.