Skip to main content
jkchoa
New Member
March 30, 2019
Question

Setting up vlan fortigate 60e

  • March 30, 2019
  • 22 replies
  • 64085 views
Hi, Can you please refer me a cookbook link, on setting up vlan for 2networks comprising of PCs and cctv ip cameras. The PCs are on 192.168.100.x and have currently gateway to the firewall for internet, while the ipcamera cctv are on different subnet 192.168.200.x, these devices needs to have routing or rather can see the other pc network and initially needs not to have internet. Really could use some examples, to get some knowledge and get started

    22 replies

    ede_pfau
    SuperUser
    SuperUser
    March 30, 2019

    This is so simple you won't need a video on it :)

     

    In order to have traffic across the firewall, the FGT needs to have one port in the VLAN. So, you create a new virtual port in System>Network>Interface, Create New, type: VLAN. It will be a sub-interface of the LAN port (or LAN switch, depending on your hardware).

    I usually assign the address .1 of the VLAN's address space to the FGT port and use it as the gateway of this VLAN. That means that all devices on the VLAN will have the FGT's port address as the gateway of their default route.

     

    Now, if you need to have VLAN traffic reach the WAN, create a policy from the VLAN interface to the WAN port.

    Same for VLAN to LAN, or VLAN to WiFi or whatever.

     

    I've seen setups where the physical LAN port was not used at all - no IP assigned. All traffic coming to and from the LAN port was VLAN traffic. If you use a lot of VLANs it might be better to create an aggregated port first (LACP), and then create VLAN ports associated with it. This will help to provide more bandwidth.

     

    Note that usually you connect the FGT LAN port to a switch. All VLANs which you intend to route/rule through the FGT need to be tagged VLANs, and the connection itself needs to be a VLAN trunk, not an access port. But if you're working with VLANs you will know that anyway.

     

    As with all ports (physical, SSIDs, VLANs, VPNs), network addresses must be unique for each port. You do not need to create routes for port LANs, this is done automatically.

    jkchoa
    jkchoaAuthor
    New Member
    April 4, 2019
    Hi again, Thanks for the above response, I tried following your procedure on setting up the VLAN as sub-interface and the policy. (I'll try to upload the screen shots) However, upon testing a laptop with IP 192.168.200.11, it cannot see the new VLAN gateway. What am I missing or did wrong? Actually am a newbie to VLAN, I tried to test it before on an HP v1910-16G switch but cannot seem to get it to work as expected from a guide I found (vmfocus) the guide was expecting that the VLAN should route naturally, but in actual the new interface cannot be PING.
    jkchoa
    jkchoaAuthor
    New Member
    April 4, 2019
    sending screen shots....
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.