Technical Tip: Configuring Access VLANs with switch-controller mode
Description | This article describes how to implement Access VLANs in FortiOS to Prevent Intra-VLAN Traffic. |
Scope | FortiSwitch. |
Solution | In standard networking, devices residing within the same Virtual Local Area Network (VLAN) can communicate directly with one another at Layer 2 without involving a gateway. While this default behavior is convenient, it poses significant security risks in modern enterprise networks. If a single host is compromised, lateral movement and malware propagation can easily occur across the entire subnet.
![]() |
