Skip to main content
jared
Visitor III
April 27, 2022
Question

FGT ZTNA Cross-Three Layer Architecture

  • April 27, 2022
  • 3 replies
  • 2001 views

topology

FGT>>>>>L3-switch>>>l2-switch >>>PC

 

 

 

Can IP/mac filtering function in this design in this architecture?
Why do you need the default gateway in FGT, this point is not very understandable to me.

Is it possible to use only IP across three layers of architecture?

 

3 replies

Anthony_E
Staff
Staff
May 1, 2022

Hello jared,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Thanks,

Best Regards
Anthony_E
Staff
Staff
May 4, 2022

Hello jared,

 

Could you please indicate us:

 

- Which models you are using?

- Which versions?

 

Thank you in advance.

 

Regards,

Best Regards
jared
jaredAuthor
Visitor III
May 5, 2022

thx your reply.

FortiGate 40F、201E

I have tried using FOS7.0.0 to 7.0.5.

FortiEMS version is 7.0.3 to 7.0.4.

Fortilcient MacOS 7.0.3 to 7.0.4  .

 

I can get the IP address through the diagnostic command "diagnose firewall dynamic list". But it doesn't work either.
I have recommended this solution to my client, but the test results so far make me doubt the feasibility of this solution.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!