Device based rule in 3 tier network with intervlan routing switch at distribution level
- March 30, 2015
- 1 reply
- 6919 views
Hi,
I'm pretty sure that this is a self answered post, but here goes...
Network has switches at the access level, all of them trunked with the company vlans to a distribution switch, which is trunked up to the fortigate - see simplified diagram network.jpg
The vlans are being routed at the distribution switch, so this switch is the gateway for each vlan. the gateway for the switch is the fortigate of course.
the trunk between the distribution switch and the forti includes the vlans also - just because i want the forti to detect the devices being connected on each vlan, other than that if i could i would eliminate this trunk.
Upon setting this up (which is a production system that had no vlans and is heavily secured with both device based rules and FSSO rules), the FSSO rules keep working great. As for the device based rules they stopped working.
My assumption is that when datagrams reach the distro switch and then are forwarded to the fortigate, the mac address at this point is the distro switch and not the client device anymore. I conclude that this is basic networking 101 and there is nothing to do here, right? no chance to use device based rules anymore.
I guess that either i would either change the set up to router on a stick (not going to happen, no need for extra hops, these vlans have intensive workload) or create extra groups and move those device based rules to FSSO rules - so for now this is my best solution to this case.
Any comments/ideas would be appreciated.
Thanks
David
