Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
Hi,
Is the above explanation still correct?
can you pl tell
1. do you have fortigate in your existing infra or you want to add new one.
2. do you want that after seting up fortigate, inter VLAN routing will be done by fortigate only?
Maybe it helps you with your decision, i could tell you how I do that here:
We have a fortigate and several switches at every shop and also here at the IT. Between us and the shops we run ipsec tunnels.
Each shop has a bunch of vlans (vids are standardized at all of them) and its own Subnets for those plus one default subnet that has no vlan..
Inter-vlan-routing and UTM and IPSec (and with that inter-vpn-routing) is done by the FortiGates.
I think that's the most easy way since basically on the fgt all you need is vlan interfaces, objects for the subnets and then policies to allow or not allow access between vlans or vlan and internet or (in our case) vpns to vlans usw.
On the Switches you then just need to to vlan setup and port-tagging. All you then need is an uplink to the fortigate which is tagged in all but one vlan (for it must be untagged in one *g* - I usually use the default vlan 1 for that and take that for the subnet that does not have a vlan). And then you just have to set your switchports to where they should be (no/forbid/tagged/untagged) depending on what you need there. Just remember if the port is tagged in vlan the device that connects to that port will have to do vlan tagging itself. If you just want the device to be just in this vlan set it to untagged in that vlan and the rest to no/forbid. In this case the switch will do the vlan tagging for the device and the fgt will do the routing.
this work fine here with FGT100E and 90Ds with an overall of 30-40 Clients per shop.
hth
Sebastian
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.