Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fabio74
New Contributor

Block two PCs from browsing within the network

Good morning everyone

Perhaps a trivial question.

I need two PCs to be able to regularly access the internet but not to browse the LAN. Basically blocks that prevent communication with Active Directory or other.
3 REPLIES 3
dbu
Staff
Staff

Hi @Fabio74 , 

Are the destinations on the same network  or different networks ? 

If same network/VLAN , intra-VLAN communication should be blocked. 

If different network you need firewall policy to allow/block traffic from/to your destinations.

I believe you need firewall policies.

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Fabio74
New Contributor

Ciao dbu e grazie della risposta.

I 2 PC sono sulla stessa VLAN è proprio quello il problema e non posso cambiare VLAN

dbu

If they are in the same VLAN you need to block the intra-VLAN traffic. 


Here is how to change the VLAN:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Changing-VLAN-interface-configuration/ta-p...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Edit-VLAN-ID-of-a-VLAN-interface/ta-p/2152...

 

 

Have a look at this documentation how to block intra-VLAN traffic: 

https://docs.fortinet.com/document/fortiswitch/7.0.8/devices-managed-by-fortios/801169/blocking-intr...

 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors