Skip to main content
azwanarif
New Member
June 23, 2019
Question

Configure vlan sub-interface as gateway for all other vlan client

  • June 23, 2019
  • 1 reply
  • 7364 views

Hi All,

I have post on creating sub-interface and create a firewall policy for inter-vlans communication which connect direct with access switch using trunk port. All communication between client and interface was successfully establish and functioning.

 

However customer goal is to use one sub-interface ( VLAN 3) as gateway for all other VLAN clients. Since the fortigate unit is located at customer place, we are unable to performed further testing and simulation. We would like to know if this method is plausible and if anyone has experience configured the same method. 

 

Lan Port (hardware switch)

Vlans 1 IP 10.101.1.254  - Client IP 10.101.1.x/255.255.255.0

Vlans 2 IP 10.101.2.254  - Client IP 10.101.2.x/255.255.255.0

Vlans 3 IP 10.101.3.254  - Client IP 10.101.3.x/255.255.255.0

Vlans 3 IP 10.101.7.254  - Client IP 10.101.7.x/255.255.255.0

Vlans 4 IP 10.101.10.254 - Client IP 10.101.10.x/255.255.255.0

Vlans 5 IP 10.101.11.254 - Client IP 10.101.11.x/255.255.255.0

Vlans 6 IP 10.101.12.254 - Client IP 10.101.12.x/255.255.255.0

    1 reply

    hubertzw
    New Member
    June 23, 2019

    I'd ask your customer why they wanted VLANs? Probably for the isolation purpose. L2, to be effective, shouldn't be large.

    It doesn't make sense to separate something first and then expect to share some pieces, like default gateway in your case.

    Do you know what is the reason behind? Why they do not want to use a separated default gateways per vlan?

    azwanarif
    azwanarifAuthor
    New Member
    June 23, 2019
    Hi hubertz, Appreciate the the feedback, what customer told us is that he prefer to separate and network for easier manage/documentation. since I don't have access to the firewall I'm using gns software and simulate the environment. As mention above the simulation is successful. However when change the client (tiny Linux) gateway, client can't reach the firewall and I'm not sure whether the system have limition or missing policy to achieve the goal.
    hubertzw
    New Member
    June 24, 2019
    azwanarif wrote:
    However when change the client (tiny Linux) gateway, client can't reach the firewall
    Can you explain what did you change exactly?