Skip to main content
gohgss
New Member
October 30, 2019
Question

DMZ Configuration

  • October 30, 2019
  • 6 replies
  • 6304 views

hello,

 

Is there anyone can share the DMZ setup at Fortigate (201E)?

Do I need to trunk the interface port and create a VLAN for this at switch?

 

Appreciate your reply for this.

    6 replies

    ede_pfau
    SuperUser
    SuperUser
    October 30, 2019

    DMZ is a LAN segment like any other, with one exception: "regard the DMZ as hacked"

    That is, no policies from DMZ to LAN!

    For instance, if you need to synchronize data between a server on your LAN and a server in DMZ, you do not pull the data from the DMZ server. Instead, you push data from LAN to DMZ (with appropriate policy).

     

    Whether you create a DMZ on a physical or a virtual port doesn't matter.

    gohgss
    gohgssAuthor
    New Member
    October 30, 2019

    I have configured it as access port in switch that connect to FW interface.

     

    Just try to find out the best practice for DMZ configuration.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!