Skip to main content
kenfung
New Member
October 10, 2017
Question

Policy routing from VLAN to internal port

  • October 10, 2017
  • 4 replies
  • 12611 views

Hi All,

 

I am setup a WIFI access for a branch office, per my attached network diagram I have setup two SSID for two VLAN.

SSID 1 : VLAN 2 for 172.16.130.0/24 ( Direct access to internet) ,

SSID 2 : VLAN 3 for 172.16.131.0/24 (Access to MPLS network , gateway : 192.168.0.2)

 

In my fortigate 100D, I have created two sub VLAN interface under LAN interface, and then I have setup a policy routing to route VLAN 2 traffic to public internet , and those client connect to SSID 1 , they can access to Internet without any problem.

 

Then I have created a policy routing for VLAN 3 , for client connect to SSID 2 for accessing to MPLS network.

My policy routing for VLAN 3 :

 

Incoming interface : VLAN 3 interface

Incoming network : 172.16.131.0/255.255.255.0

Outgoing interface : LAN

Outgoing network : 0.0.0.0/0.0.0.0

Gateway : 192.168.0.2

 

BTW, I have create policy to allow 172.16.131.0 network to access 192.168.0.2, also 192.168.0.0/24 able to access VLAN 2 and VLAN 3 network.

 

However, when client connect to SSID 2 (VLAN 3) , seem they are unable to access MPLS network.

So is there any misconfiguration ?  And how do I routing VLAN 3 traffic via MPLS gateway ?

The reason for those WIFI network differ from LAN subnet, I would like to isolate wireless client against to LAN subnet.

 

Thank you for your help.

    4 replies

    MikePruett
    New Member
    October 12, 2017

    Just to verify your policy for MPLS is currently set to

    Source Interface: VLAN3

    Source Address: 172.16.131.0

    Destination Interface: LAN (MPLS subnet switch ports)

    Destination Address: 192.168.0.2

    ?

     

    If so, you need the destination address probably to be all (or any and all networks that exist on the MPLS you want them to access). Otherwise, you will only be able to talk to the .2 device and nothing past it.

    kenfung
    kenfungAuthor
    New Member
    October 12, 2017

    MikePruett wrote:

    Just to verify your policy for MPLS is currently set to

    Source Interface: VLAN3

    Source Address: 172.16.131.0

    Destination Interface: LAN (MPLS subnet switch ports)

    Destination Address: 192.168.0.2

    ?

     

    If so, you need the destination address probably to be all (or any and all networks that exist on the MPLS you want them to access). Otherwise, you will only be able to talk to the .2 device and nothing past it.

    Hi Mike,

     

    Thanks for your quick reply, for what I have configured is "

    Source Interface: VLAN3

    Source Address: 172.16.131.0

    Destination Interface: LAN (MPLS subnet switch ports)

    Destination Address: 0.0.0.0/0.0.0.0

     

    Gateway : 192.168.0.2 (MPLS gateway)

     

    HERBINET_Maxime
    New Member
    October 12, 2017

    Hi,

    Could you post the output of :

    #> get router info routing-table database

     

    You need both active route through Internet & MPLS.

     

    Also, I advice you to create a "Stop Policy Routing" for any RFC1918 ip address, before your existing PBR.

    This will restore a normal behavior/routing for InterVlan traffic.

     

    BR,

    Max

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!