stealth bridge to filter traffic within same LAN segment
- February 5, 2019
- 0 replies
- 1802 views
Hi,
I'm new to Fortigate, and I'd like to set up a really simple bridge.
Suppose I have a LAN switch with hosts within 192.168.0.1-10. I then connect a Fortigate between this switch and another. On the second switch I have hosts 192.168.0.11-20.
I want these two groups of hosts to be able to connect to each other through the Fortigate (so I can see all sessions).
So imagine I connect switch1 to port WAN1 or LAN Port 1 on the Fortigate, and switch 2 to WAN2 or LAN Port 2 (whichever).
I then add IPv4 policies so I "accept all" traffic:
1) from WAN1 to WAN2
2) from WAN2 to WAN1
3) from Port1 to Port2
4) from Port2 to Port1
I also want to configure the management interface with IP addr. 10.1.1.1/16. It is physically connected to another switch/network.
I supposedly have it all configured, but I see no traffic flowing between both interfaces (WAN* or Port*).
Can anyone please give me some genral pointers (or CLI commands) to make this happen?
It basically needs to be a transparent bridge within the same suibnet so I can analyze/filter traffic.
Thanks,
Vieri
[EDIT] Please find attached several screenshots. WAN1, WAN2, Port1 and Port2 are configured alike. I would like to bridge any set of WAN1+WAN2 or port1+port2. Then simply monitor traffic flowing within this or these bridge/s.
[EDIT] Virtual Wire Pair... is that the way to go?
