Hi everyone,
I'm currently managing a main site protected by a FortiGate 60F and two remote sites equipped with MikroTik RB2011 routers. The sites are interconnected via a Microwave (Wireless) link acting as a direct private routed connection (no public internet involved).
I need to connect the two remote subnets to my main network so that:
All machines can ping each other across sites.
Remote machines can reach the main site's Active Directory controllers to join the domain and authenticate properly.
What is the best approach for static routing and firewall policies on the FortiGate?
Should I simply create network address objects for the remote subnets and allow specific Active Directory ports (DNS, Kerberos, SMB, LDAP, RPC, etc.) coming from the microwave interface towards my servers?
Are there any specific pitfalls or best practices to keep in mind (e.g., disabling NAT, handling dynamic RPC ports, proper routing on the RB2011 side)?
Any advice, configuration best practices, or sample setups would be greatly appreciated. Thanks!
Source: r/fortinet · by /u/Icy_Attorney_4692