Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
avilt
New Contributor

200E in Transparent Mode

I have a flat subnet (single subnet). Can I implement 200E firewall in transparent mode to enforce firewall policies?

I have a couple of servers at my location which will be connected to a difference location. At the moment all are in a flat subnet and changing IP schema is ruled out.

 

10 REPLIES 10
ede_pfau
SuperUser
SuperUser

hi,

 

yes of course you can. You can define policies in TP mode, as well as protection (UTM) etc.

TP mode is most often used if the FGT is behind another firewall, or for testing purposes. It doesn't require to change any of the settings of the network the FGT is deployed to.

I recommend the FortiOS Handbook on docs.fortinet.com for an overview and the details of TP mode.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

To clarify,you can   enforce policy between  traffic-pairs ( ingress/egress ) , so traffic entering the flat subnet can be policed but not  West-East traffic  in the flat subnet. So basically North-South bound traffic flows.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
avilt
New Contributor

Attached is the block diagram and I need to enforce the policies between two locations which are in the same flat subnet.

Please advise.

emnoc
Esteemed Contributor III

That should work if you have a traffic-pair in/out between the two local-lan-segments.

 

I.e

 

LAN01-SEGMENT-01    <port1     -------port2>  LAN02-SEGMENT-O2

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau

in short words, traffic must flow through the FGT in order to control it. (anything else would be magic.)

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
avilt
New Contributor

Thank You.

 

I believe in this setup, ARP messages cannot be filtered between two segments. Is there a way to achieve this requirement?

emnoc
Esteemed Contributor III

No  but broadcast/multicast traffic could. I don't think you can filter a specific ARP request at a layer2  FW.  Some one could correct me on this.

 

So if your goal is to filter ARP, I would ask why ? And what do you want to gain ?

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
avilt
New Contributor

I have a large number of firmware based devices (10mbps/half duplex) and I want to limit the ARP broadcast reaching these devices. 

emnoc
Esteemed Contributor III

Never seen that done but you  can segment lsolate and have   policy from port1--port2 and port1---port3 if you need a finer  control of traffic flows.

 

To write a ARP as a SRC/DST I don't believe is possible. PaloAlto or Forcepoint could possible do this. You can control layer3 src/dst in the fwpolicies with  easy. I would look at a  isolated L2-template. See this jpg for a possible solution.

 

 

Ken

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors