- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How route 1 vlans internet traffic through a proxy on another vlan?
Could someone, as if they were speaking to a child, explain the steps and infrastructure I would need to accomplish this:
I have a Fortigate 60e firewall.
I have been tasked with setting up a network with 4 VLANs with different subnets. VLAN1 contains a proxy server and there is to be no internet access except through this proxy for both VLAN1 AND VLAN2. VLAN 3 and 4 I can control normally with the 60e policies.
So far I am thinking, create 4 vlans in the 60e.
Vlan 3 and 4 are fine to deal with normally.
Now I just don't understand networking enough to know what to do from here.
How do I set up a proxy on VLAN 1 (squid?) and then how do I get traffic from vlan2's subnet going over to vlan1's subnet and going through the proxy? How does that work?
Gateways, switches, broadcast domains, multiple subnets???
Could someone please give me a little guidance here?
I feel out of my depth here so thanks for any help guys :)
Jono
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Orestis Nikolaidis
Network Engineer/IT Administrator
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you are only talking about web traffic, look into explicit web proxy :
If you are terminating the L2 vlans on the Fortigate this shouldn't be a problem.
Web proxy is configured in the browser in most cases , like in Firefox :
Preferences -> Network Settings -> Manual proxy configuration
NSE7, FMG, FAC, FAZ .
1500D's, 1200D's, 900D's, 300D's, 200D's, 100D's and bunch of small stuff.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Guys thanks so much for the help... I am trying to implement now. Will let you know how it goes!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to follow up, this worked great. Fortigates are awesome!
