Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

Intra vlan security profiles

Hi 

I want to secure vlans to vlans traffic with my 200f fgt. Which security profiles can i enable between vlans?

Reza F.
Reza F.
7 REPLIES 7
ozkanaltas
Contributor III

Hello @rezafathi ,

 

In my opinion, IPS and AV are enough for these traffics. You can configure it with the default profile on your policy or you can customize the profile according to your preferences.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
rezafathi

Thanks. Should i use deep ssl profile or not?

Reza F.
Reza F.
ozkanaltas

Hello @rezafathi ,

 

This is generally not recommended for internal traffic. If you do a deep inspection, many applications may not work and you will need to install a certificate on each client.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
rezafathi

If i dont use deep inspection av would not work

Reza F.
Reza F.
ozkanaltas

This is partly true. If the protocol used is not secure, it will detect viruses. However, many protocols are sensitive. If you do deep inspection it won't work. That's why deep inspection is often used for web traffic.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
rezafathi

So can i disable ssl inspection?

Reza F.
Reza F.
ozkanaltas

My advice is, yes you can close.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Labels
Top Kudoed Authors