Skip to main content
journeyman
New Member
August 9, 2017
Solved

options to segregate host on a LAN

  • August 9, 2017
  • 14 replies
  • 37444 views

We have a /24 LAN configured on a vlan interface. It has been requested to segregate one host on the LAN so it can only reach other LAN hosts via defined policies.

Is it possible to do this without changing the host IP address, subnet and default gateway?

 

For instance, is there any way that can two VLANs be treated as one interface in terms of their subnet but control traffic between them using policies?

We have a lot of flexibility with VLAN configuration. We do not currently use zones but I do not believe this would help.

The managed switches support private VLAN, but this is not an option since we have multiple switches on the LAN (the privacy setting is restricted to the local switch only).

 

From what I can see this is not possible, but it is certainly worth asking.

 

If there are no other options we'll just assign a new IP range to the host and proceed with a regular layer 3 solution. But it would be very nice to do this somehow "in the background". And it would be very useful elsewhere - Oh, all those stray devices I could isolate!

Best answer by Kenundrum

Vdoms add up on smaller devices because in effect you spawn worker processes for each vdom separately. Also it becomes a chore to synchronize address and custom service lists between them. The primary reason for vdom separation is to have a firewall that operates in transparent and NAT mode at the same time or for administrative separation. You can set minimum and maximum values for certain resources like vpn tunnels, policies, and sessions but not really a maximum/minimum CPU/memory so resource management on smaller boxes can be tricky if you're using a lot of UTM functions.

14 replies

ede_pfau
SuperUser
SuperUser
August 9, 2017

IMHO you can only police / manage this host's traffic on the FGT if it traverses the FGT. This implies routing at least, so you will have to change the host's address or net mask. It just won't use the FGT if addressing other hosts in the same subnet.

On the FGT you then have the device dependent policies to do whatever you like.

journeyman
New Member
August 10, 2017

By asking here I was hoping to discover an sufficiently advanced technology of which I was ignorant :)

 

I know it is necessary to force the traffic to traverse the FGT; it is easy to do that by applying a new subnet but was hoping the FGT could somehow magically have one subnet on two interfaces and force the traversal that way, or something.

 

And if this magic existed, it would then be possible to isolate any device on our networks at will, and oh how powerful that would be.

Iescudero
New Member
August 10, 2017

Hi there!

The only way to achieve this is if the traffic goes through the firewall, we're all agree with that, but that doesn't mean that you have to create a new subnet or vlan to do that.

You can do this putting your fortigate in transparent mode:

"...A FortiGate in Transparent mode is installed between the internal network and the router. In this mode, the FortiGate does not make any changes to IP addresses and only applies security scanning to traffic. When a FortiGate is added to a network in Transparent mode, no network changes are required, except to provide the FortiGate with a management IP address. Transparent mode is used primarily when there is a need to increase network protection but changing the configuration of the network itself is impractical..."

 

Hope it helps!!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!