Creating Fortigate subnets vLAN's for VMWare hosts.
Hello,
I am new to Fortigate and I am sure I am missing something here. To be honest, not even sure wether it is a Fortigate or VMWare problem.
Here is my case: My Fortigate 60D is directly connected to two vmware 6.x hostservers. Not using any another physical switch, just the internal 7+1 hardware ports switch on the Fortigate.
On the VMWare hostservers there need to be separate networks. So I choose to use 172.16.0.0 (255.255.255.224) giving me about 23 possible subnets with 30 hosts, like this;
subnet 0 255.255.255.224 172.16.0.1 - 172.16.0.30 subnet 4 255.255.255.224 172.16.4.1 - 172.16.4.30 subnet 8 255.255.255.224 172.16.8.1 - 172.16.8.30 and so on.
So the internal Fortigate interface (and gateway) is set to 172.16.0.30. The subnets 4,8, and 12 were created as vLAN's. On the vmware server I use a standard virtual switch. Subnet 0 is used for the internal hardware (server NIC's, HP ilo port, storage server and so on.) A firewall object and security policy was created for this subnet. Al hosts are able to commicate witheach othe and to the outside world. This works fine.
For the other subnets different vlan's (port groups in vmware terminology) are created. In each subnet I used the last (.30) address as the default gateway for that particular subnet. These VM's are able to communicate with each other but not to the outside world. Created a Firewall object and Policy for these subnets, on the same way I did that for the internal network 0. But only the internal subnet 0 is able the reach the outside world.
Now what am I missing here? Is this even possible without an extra switch?
I hope someone is able to see the problem. Thanks in advance.
Eric Loderichs
