Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Technician-109
New Contributor II

Network Configuration Help

What's up all. Novice at networking here, bear with me. Trying to dump my cheap home firewalls and go with the real thing. Looking to purchase a Fortigate Firewall and Catalyst 1200 Series Switch. Pretty basic setup. I need to:

  1. Create VLANS and have them access the internet

  2. Completely isolate the VLANS at Layer 3

I have been looking at a few different ways to do this but need help. I can figure out most of the config but could use assistance with the design / have a few config questions.

 

Would you:

  1. Go layer 2 VLANS at the switch and then tag them up to the firewall and create firewall policies to separate the VLANS? Would I even need to tag them on the firewall?

  2. Would inter-vlans need to be created on the firewall to deny all traffic or could I just create firewall polices for each lan and have the switch handle the tagging?

or

  1. Go Inter-vlan on the switch and create ACLS on the switch as opposed to having the firewall do the work. It seems strange to me to have a firewall perform switching functions as I am trying to separate this all out.

Performance is not a concern as this is a basic network, security is top of mind. Thanks to anyone that can help.

2 Solutions
vbandha
Staff
Staff

Hi @Technician-109 
You would need to create VLANs on the fortigate. Here is a guide for that:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-create-a-VLAN-tagged-interface-802-...

You will also need appropriate firewall policies on fortigate for inter vlan routing and any other access

By default firewall will deny access so you don't need deny policy between vlans.

I agree that switch side you could leave as basic setup

 

Especially considering security aspect, you want firewall to be handling all this routing so you can apply security profiles if needed. 

 

Regards,

Varun

View solution in original post

Toshi_Esumi

And, for No.2, you just need to create different sets of protection profiles Webfilters/IPS sensors, then use them in different sets of policies per VLAN interface (source interface) to your wan interface(s) (destination interface).

Toshi

View solution in original post

10 REPLIES 10
Technician-109

Thanks, @SabtainSaleem

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors