Separate LAN hosts
Hello,
i have similar needs as described here:
https://forum.fortinet.com/tm.aspx?m=151527&tree=true
I have hosts on a vlan which i want to separate.
I do not want to change the HOST IP. At the moment hosts are in one vlan.
so i have created a vdom in transparent mode.
i have added 2 VLANS (VLANID 990 and 991) to Fortigate Ethernet Port3.
I have connected this fortigate port to switch port (HP Procurve).
I have configured the switch port to tag VLAN 990 and 991 (similar to CISCO trunk port).
i have configured 2 other switch ports with untagged VLAN 990 and vlan 991 (similar to cisco access port).
On every untagged/access port a devices with IP (within same subnet) connected.
Both devices can not directly communicate, so the traffic should go to the trunk port which is connected to the fortigate.
On the fortigate i have configured 2 policies to allow any traffic from "VLAN990 to VLAN991" and "VLAN991 to VLAN990".
But there is no communication possible.
I have added a forwarding domain (ID 11) to both interfaces, VLAN990 and VLAN991.
But also no traffic possible.
I thought this could be possible, after i read the forum entry mentioned at the beginning.
Maybe somebody can help me?
Regards
Marc
