How to achieve Layer 2 (Intra-VLAN) traffic visibility and blocking on FortiGate 7.2.12
Hi Community,
I am currently using a FortiGate running FortiOS v7.2.12. My FortiGate is configured as the Gateway (L3 mode) for my network segments.
Coming from a Palo Alto background, I am used to having visibility into Layer 2 traffic. I would like to achieve similar visibility on the FortiGate for Intra-VLAN traffic (devices communicating within the same subnet).
My goals are:
Visibility: To see/log traffic between hosts in the same VLAN.
Control: Ideally, I want to be able to block this L2 traffic if necessary.
Since the FortiGate is the gateway and traffic usually switches locally on the access switch without hitting the firewall:
Is there a specific configuration required on the FortiGate side (e.g., specific interface settings, policies) to intercept and log/block this L2 traffic?
Would enabling Deep Packet Inspection (DPI) help in this scenario to gain visibility, or is this purely a routing/switching issue?
Do I need to implement Private VLANs (PVLAN) on the switch side and enable proxy-arp on the FortiGate, or is there a "Transparent" feature I can enable on an L3 interface?
Any advice or best practices to achieve "East-West" lateral movement visibility within the same VLAN would be appreciated.
Thanks in advance.