VIP Between VLANS and Broadcast
From the docs it looks like this might work, but wanted to check here before trying it out.
TL;DR version: Will a VIP between VLANS on the FortiGate (5.4.6) do both proxy-arp and forwarding of L2 unicast and broadcast? How about multicast?
Longer version:
I've got a couple networked printers in a separate vlan and subnet, accessed by IP through the FortiGate from a secure lan with its own vlan and subnet. I only allow initiation of the connection from the lan side, not the printer side. This works okay, except for two things. Adding a Windows 10 printer tends to fail to find the printer, even when given its IP, and the printers' remote scanning software fails completely if the printer isn't in the same subnet.
So, I'm considering creating a VIP on the lan side mapped to each of the printers in the printer vlan. This still lets me control initiation of the connection through security policies (with match-vip as needed) and I think should allow the Windows 10 printer drivers to think the printer is within their own subnet.
Does this seem reasonable? I'm open to suggestions for a better way to handle this.
