Firewalling traffic between hosts located in the same VLAN
Hello.
We are trying to achieve the following: traffic between hosts (a bunch of VMs, actually) has to be proctected by a firewall, but these hosts are located in the same L2 VLAN and use a matching L3 addressing subnet.
The problem is not that we simply need to isolate the hosts that belong to the same VLAN (Private VLANs could be used for this purpose), they still need to communicate with each other and we need to firewall all of their communication.
Further segmentation of the VLAN (into smaller networks) is just not feasible.
Does anyone have an idea how to do this the best way in the Fortigate world? Would any features of the "new" Security Fabric be of any use here?
Thanks for your help!
