I have a flat subnet (single subnet). Can I implement 200E firewall in transparent mode to enforce firewall policies?
I have a couple of servers at my location which will be connected to a difference location. At the moment all are in a flat subnet and changing IP schema is ruled out.
avilt wrote:I have a flat subnet (single subnet). Can I implement 200E firewall in transparent mode to enforce firewall policies?
I have a couple of servers at my location which will be connected to a difference location. At the moment all are in a flat subnet and changing IP schema is ruled out.
Hi there,
So your network in layer-2 level, should be isolated by the TP firewall. I mean, if you put your TP firewall between your clients and servers, then these two sides should be isolated in layer 2.
Plugging 2 ports of TP firewall into one vlan would cause layer 2 loop and create broadcasting storm throughout your network.
You put server side and clients side into two vlans, and create a policy to connect these 2 vlans, so you could implement a policy to filter ARP between them.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.