VLANs, Routing, and NATs
- February 26, 2016
- 6 replies
- 6949 views
We are a K-12 school district, trying to VLAN our network.
The VLANs are setup on the switches, and interfaces for each have been created on the Fortigate.
We are using the Fortigate unit as the gateway for each VLAN.
We have a web filter in place, as well as a ISP load balancer. All units are VLAN-aware, and are configured.
I want to use the Fortigate as the main router for our district.
In the example, we have 4 VLANs.
Servers - VLAN 1
Teachers - VLAN 65
Students - VLAN 66
Public Wireless - VLAN 99
VLAN 1 clients/servers need to be able to access the internet.
VLAN 65 clients should be able to get to Server #1 (Port 80), Server #2 (Port 80), and the internet.
VLAN 66 clients should get to Server #2, and the internet.
VLAN 99 clients should only get to the internet.
If I set the gateway of the clients to their respective web filter gateway ( vs the Fortigate gateway ), they get to the internet fine, but are unable to access other servers.
I've messed with default static routes for eachs interface, a mix of static and policy routes, but I'm unable to satisfy what I want.
I'm having trouble getting this setup going - Any direction please?
Thanks!
I've attached a diagram.
