Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
LAN AND DMZ On same subnet
Dear Fortigate Team,
I have a small doubt is it possible to create Two zones ( for example LAN and DMZ ) and then configure same Network subnet on both zones.
My customer is asking me to create 2 security zones and both zones devices should be on same subnet .
2 REPLIES 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Even if it were possible, how would you force the traffic through the firewall? If the LAN devices share the subnet with the DMZ devices they will directly communicate over any generic layer 2 devices (switches) that might be involved. If there is somehow physical separation it still will not work as routing between the two would be impossible. Maybe break the one subnet into two?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You will have a routing problem , as mentioned above.This design is not following best practices and it's not recommended.
If the customer still insists to have this network solution you will need VDOMs enabled and configured .
