Skip to main content
Zydrunas
Explorer
October 7, 2022
Question

Same FortiGate subnets for multiple endpoint users

  • October 7, 2022
  • 10 replies
  • 5422 views

Hello to all,

 

i have a difficult task to do. I need to create same subnets for multiple endpoint users and isolate those subnets without using multiple routers firewalls.

Can't figure out how to do it and if it is possible at first place.

ydrnas_0-1665123907353.png

 

Thank you.

10 replies

jintrah_FTNT
Staff
Staff
October 7, 2022

Hi,

You may think of using 3 vdoms and each subnet on any segment under different/unique vlan ids so that same subnets may overlap with different vlanids connecting to different vdoms.

 

cheers,

Jin

aahmadzada
Staff
Staff
October 7, 2022

I would go for the Private VLANs as a more elegant, easy to deploy solution

 

https://docs.fortinet.com/document/fortiswitch/7.0.1/administration-guide/104079/private-vlans

Zydrunas
ZydrunasAuthor
Explorer
October 7, 2022

Using private VLANS like @aahmadzada suggested looks like truly more elegant solution if it is really possible to fulfill this task using PVLANS. Using VDOMS like @jintrah_FTNT suggested is more complex solution and create more mess since we need to enable VDOMS functionality which is not used and is disable by default.
@aahmadzada can you share some print screen or examples how to implement my task from your test FortiGate device ?

 

Thank you.

gfleming
Staff
Staff
October 7, 2022

What is your actual goal here? You want to block endpoint from communicating to each other regardless of what subnet they are in? Or you want to isolate endpoints only from other endpoints that are in different switches? Or you want to isolate endpoints between different subnets. If it's the latter, you can just use Firewall Policies. If it's one of the two formers we can look at other options.

 

It's an odd set up. I wonder if there's a better way of doing what you're setting out to do. More details you can provide the better!

Zydrunas
ZydrunasAuthor
Explorer
October 7, 2022

The goal is that our company has a lot technical engineers working as technical support for all kind of network equipment like (IPC's, switches, routers, NVR's, etc..) returned as for warranty service from clients, or returned from shops to reinstall firmware's, etc.
And by default devices comes with default subnets like:

192.168.0.0/24
192.168.1.0/24

192.168.10.0/24
192.168.90.0/24
192.168.64.0/24
192.168.254.0/24

etc..

So each tech. engineer is working with same devices at the time connecting them to same network creates an IP conflict because devices by default have same default IP's like 192.168.0.1, 192.168.1.1, etc..
To avoid this tech. enginees right now use their own routers in eatch workplace to separate same LANS and keep them behind NAT. Imagine 10 or more tech. engineers connecting routers to your LAN crates a big mess with wires, and network configuration. I want to avoid that and searching for more elegant solutions without using router in each workplace.

gfleming
Staff
Staff
October 7, 2022

OK in this case private VLANs  may not work. Since by default the hosts in a secondary PVLAN can still communicate with the primary VLAN. So the FortiGate will see lots of duplicate IP addresses. Might still work for local device access though. I.e. Tech Laptop and IPC are in community VLAN 202, they will not see laptop and IPC in VLAN203 with same IP but FortiGate with Primary VLAN 201 will see them and the IP conflicts.

 

Do the workstations have multiple NICs? Is it possible to have dedicated NIC for connecting to the warranty devices and another NIC (even if its just wi-fi) for all other network connectivity?

 

If so, then you can just set up individual L2 VLANs for each tech. Plug the NIC into one port in the VLAN and plug the devices into the other ports in the VLAN. The tech can manually change their IP address to service the gear on that wired connection to the VLAN (no default gateway). The primary NIC will have default gateway and won't change IP address.

 

If that's not possible then I think best option is to consider PVLANs but might have issue with FGT seeing duplicate IPs. Or you can consider VRF where each technician's VLAN is put into a different VRF ID. VRF allows overlapping IP space.

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.