Is it possible to put a Fortigate in the middle of a network with arbitrary parts on either side
Hi folks,
I'm replacing a Palo Alto PA-3220 with a Fortigate 3001F. Our Palo is at our research site and it has some things behind it and some things in front of it. It does routing for a few RFC1918's that are behind it, but all the rest of the routing is done on the outside. Arbitrary hosts are behind the Palo in arbitrary subnets and vlans, and other hosts in the same subnets and vlans are not behind it. The Palo seems to handle this just fine using layer 2-only vlan interfaces and I can assign multiple of those to the same zone even though they're on different physical interfaces and then just assign policies based on address and zone and it doesn't care that the subnet is spread across two interfaces - it's not doing the routing anyway... the Fortigate seems to really want subnets to exist on one side of the unit or the other, and I can't have floating VLAN interfaces that aren't attached to any physical interface like you can on most other network devices I've worked with, unless I'm missing something. Is there anyway to tell it not to do routing for particular subnets and just apply policies to traffic across the unit, and then do routing for other subnets? For instance, I want, say, 201.162.80.5, a host in the 201.162.80.0/24 subnet and vlan 80, to be behind the Forti, even though the gateway for that subnet is outside the Forti, at 201.162.80.1 on a vlan80 interface on our router, and also the Forti itself has an address on the outside interface in that subnet and VLAN, at 201.162.80.4 . I cannot figure out how to make it so the Forti knows the gateway for the subnet is on the outside interface but that particular host is inside. Can this be done? Thanks in advance!
