Skip to main content
firewalled
Visitor III
July 9, 2019
Question

Vlans

  • July 9, 2019
  • 6 replies
  • 5379 views
Good day to you all! I have created 4 vlan interfaces on my fortigate 90d. I can ping all the computers from different vlans. My question is, since we do not have any domains (servers) , Is it possible that I can see all of the machines in a single workgroup or can ping using their respective computer names? Thanks!

    6 replies

    rwpatterson
    New Member
    July 9, 2019

    I believe that all depends on if the protocol that the workgroups are using is routeable. If you register the names in DNS then they should be reachable by good old TCP/IP. It has been quite some time since I messed with workgroups.

    Grave_Rose
    New Member
    July 9, 2019

    Hey firewalled,

     

    From what I understand of Windows and NBT, the broadcasts for Workgroups won't leave a subnet so as long as your VLANs are independent links (which they have to be), they won't see each other. If you want to access them by name, you'll need a DNS server or you'll have to manually create hosts files on each box.

     

    Hope this helps,

     

    Sean (Gr@ve_Rose)

    sw2090
    SuperUser
    SuperUser
    July 10, 2019

    this is not a vlan issue - it is a dns issue. You will need a DNS Server that can resolve all the computer names.

    We have an AD here and our AD Controller acts as DNS and resoves the name of any client in any subnet in any shop and so I can ping it.

     

    Thus I am unsure about browsing workgroups....

    haithm
    New Member
    July 15, 2019

    sorry ,

    you have created 4 vlan interfaces on your fortigate 90d. you can ping all the computers from different vlans.

     

     i created all cnofiguration for vlans and i can ping to the gateway for each vlan 

    but i can not pin to computers what is the problem   please can you explain what are you done .

    thank you 

     i'm so sorry , 

    sw2090
    SuperUser
    SuperUser
    July 15, 2019

    well to enable inter-vlan-traffic so you can ping any host in any vlan from any other you need to set up the corresponding policies. You do not need to set up static routes. Routing is already there because of the vlan interfaces.

    If there is no policy that matches your traffic it will hit policy #0 which is always the last policy in the list and matches all traffic and denies it.  So unless your traffic from one vlan to annother hits annother policy it will be denied!

     

    With setting up Policies keep in mind that in FortiOS Policies are first come first server from top down. So the first policy that matches your traffic will "win" and the rest will not come to effect.

    Leen
    New Member
    July 18, 2019

    Netbios uses broadcast, setup multi cast between your vlans and they all will see each other. you might have to enable this feature first to be able to do this.

    You have to do the same for devices like apple TV if your itunes server is on a different subnet.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!