If you use no a second one and you DO NOT configure the second one as secondary IP on the wan1 (not needed) but instead you configure a VIP based on the second one all works from scratch as long as the second public IP is routed to the wan1 from outsite perspective. Example: if you have one public IP on the wan1 and it is physical configured you will see the arp no problem. What has to be noted in this comunication is following:ĪRP entries on a FortiGate configured as whatever on a physical interface can be seen with the corresponding commands shown here like:ĪRP entries like VIP ones CAN NOT BE SEEN on the arp list because they are existing in the firewall deamon on layer 4.