ER7412-M2 interconnected to Fortigate
My setup is I have fortigate firewall interconnected to ER7412-M2 (LAN of fortiate to WAN of ER7412)
I configured routing on both sides and firewall policy on fortigate to have communication to local subnets of ER7412-m2 and fortigate firewall.
Now i can communicate from local subnets of ER7412-M2 to local subnets of Fortigate but vice versa I can't communicate local subnets of ER7412-M2 from fortigate local subnets, I can only ping the LAN gateway in ER7412-M2 but the local device is not.
I think it has somethin to do in NAT of ER7412 but there is no option to disable it.
How can I possibly fix this issue. Thank you!
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Hi @Ataris, it might be easier just to connect the Fortigate firewall to a LAN port on the ER7412-M2 instead of it's WAN port.
- Copy Link
- Report Inappropriate Content
Hi @Ataris, it might be easier just to connect the Fortigate firewall to a LAN port on the ER7412-M2 instead of it's WAN port.
- Copy Link
- Report Inappropriate Content
@D-C Oh yes. I never thought of that. This will make things easier since the firewall will do everything. I will try that. Thanks
- Copy Link
- Report Inappropriate Content
The latest firmware V1.1.0 for ER7412-M2 V1 adds a “Disable NAT” option—you can use this feature to meet your requirement.
- Copy Link
- Report Inappropriate Content
@Ethan-TP Actually this is my setup current setup after update same problem. still i cant ping host at er7412-m2. or maybe acl config? previously i cant ping er7412-m2 Lan gateway when i configured ACL rule on er7412-m2
Policy = Allow
Service type = All
Direction = wan in
Source = IP Group Any/Fortigate LAN Subnets
Destination = ME
This solved me to ping LAN Subnet of ER7412-M2
Then i Tried to Add additional rule
Policy = Allow
Service type = All
Direction = wan in
Source = IP Group Any/Fortigate LAN Subnets
Destination = IP Group Any/ER7412-M2 LAN Subnets
Policy = Allow
Service type = All
Direction = wan in
Source = IP Group Any/ER7412-M2 LAN Subnets
Destination = IP Group Any/Fortigate LAN Subnets
- Copy Link
- Report Inappropriate Content
Perhaps you should configure it exactly as described in the setup guide I provided.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@Ethan-TP This is from fortigate LAN subnet perspective. LAN of ER412 no response but vice versa ping is ok.

- Copy Link
- Report Inappropriate Content
