I have a flat subnet (single subnet). Can I implement 200E firewall in transparent mode to enforce firewall policies?
I have a couple of servers at my location which will be connected to a difference location. At the moment all are in a flat subnet and changing IP schema is ruled out.
hi,
yes of course you can. You can define policies in TP mode, as well as protection (UTM) etc.
TP mode is most often used if the FGT is behind another firewall, or for testing purposes. It doesn't require to change any of the settings of the network the FGT is deployed to.
I recommend the FortiOS Handbook on docs.fortinet.com for an overview and the details of TP mode.
To clarify,you can enforce policy between traffic-pairs ( ingress/egress ) , so traffic entering the flat subnet can be policed but not West-East traffic in the flat subnet. So basically North-South bound traffic flows.
Ken
PCNSE
NSE
StrongSwan
That should work if you have a traffic-pair in/out between the two local-lan-segments.
I.e
LAN01-SEGMENT-01 <port1 -------port2> LAN02-SEGMENT-O2
PCNSE
NSE
StrongSwan
in short words, traffic must flow through the FGT in order to control it. (anything else would be magic.)
Thank You.
I believe in this setup, ARP messages cannot be filtered between two segments. Is there a way to achieve this requirement?
No but broadcast/multicast traffic could. I don't think you can filter a specific ARP request at a layer2 FW. Some one could correct me on this.
So if your goal is to filter ARP, I would ask why ? And what do you want to gain ?
Ken
PCNSE
NSE
StrongSwan
I have a large number of firmware based devices (10mbps/half duplex) and I want to limit the ARP broadcast reaching these devices.
Never seen that done but you can segment lsolate and have policy from port1--port2 and port1---port3 if you need a finer control of traffic flows.
To write a ARP as a SRC/DST I don't believe is possible. PaloAlto or Forcepoint could possible do this. You can control layer3 src/dst in the fwpolicies with easy. I would look at a isolated L2-template. See this jpg for a possible solution.
Ken
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.