Skip to main content
Henkert
New Member
December 9, 2015
Question

VDOM's, Links, VLAN's and WAN

  • December 9, 2015
  • 6 replies
  • 6174 views

Hello Fortinet Forums,

 

I've had some contact with people in the Fortinet subreddit but couldnt quite fix my problem. Also the time difference is a big problem for me because I have access to the fortigate unit at different times than when those people can assist me.

 

Currently I am a student using a Fortigate 200b (FortiOS 5.2.4) which will be used in production in a few months. Now my task is to configure that Fortigate and make it ready.

my class has 6 groups of students that all have 1 public IP address.

Every port has it's own subnet for every single group. I've done this with seperate VDOM's.

Now all ports need to get a public IP Address too.

Now I configured that with 1 port that gets all the IP Addresses from another router.

That currently is let's say, port 10.

Under that port i've configured 6 subinterfaces that all have it's own VLAN.

All those single VLANs are in the same VDOM as where they belong.

I've made a static route which is; 0.0.0.0 / 0.0.0.0 > Gateway

I've made a policy that will allow the traffic between inbound and outbound.

 

Now here's the problem.

I can ping the external IP addresses and receive a reply, but when i plug a laptop into one of the ports it does not get internet access or anything. I'm out of options how to fix that.

 

Anyone that can assist me?

 

regards,

    6 replies

    Henkert
    HenkertAuthor
    New Member
    December 14, 2015

    Sadly no answers.

    ede_pfau
    SuperUser
    SuperUser
    December 14, 2015

    hi,

     

    sorry, all the others are busy...

    Your setup sound quite a bit convoluted to my simple ears but I'll try.

    First, have you enabled NAT on the outgoing policy?

    Which leads to the next question: if you plug in a PC at one port, which VLAN does it use then? Is there a policy from that VLAN to "wan", again with NAT enabled?

    Henkert
    HenkertAuthor
    New Member
    December 14, 2015

    Isnt an Any / Any rule in the firewall solving both those problems for testing

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.