Question
How does Fortigate Handle Multiple Internal Networks
Hi, I have a network with 192.168.1.0/24 subnet with an inside LAN physical interface 192.168.1.7 connected to Fortigate 200B firewall. There is a requirement to break the internal network into 2 subnets. This means the internal network will contain 192.168.1.0/24 network range and 10.0.0.0/16 network range once the solution is implemented. Does this mean I have to create a virtual sub interface or a physical interface within the firewall to serve the traffic for the new network of 10.0.0.0/16? Meaning should the firewall have a zone (interface) representing each internal network to support policies for both networks? Or isn' t possible to create a completely isolated 10.0.0.0/16 network connected to 192.168.1.0 network internally and route the 10.0.0.0/16 traffic via 192.168.1.0 network to the firewall gateway of 192.168.1.7? Will the firewall drop traffic if it receives packets sourced from 10.0.0.0/16 subnet from 192.168.1.7 physical interface even if the policy is created to allow traffic? Please advise :) Thank you in advance. Thilina
