Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
firewalled
New Contributor

Vlans

Good day to you all! I have created 4 vlan interfaces on my fortigate 90d. I can ping all the computers from different vlans. My question is, since we do not have any domains (servers) , Is it possible that I can see all of the machines in a single workgroup or can ping using their respective computer names? Thanks!
6 REPLIES 6
rwpatterson
Valued Contributor III

I believe that all depends on if the protocol that the workgroups are using is routeable. If you register the names in DNS then they should be reachable by good old TCP/IP. It has been quite some time since I messed with workgroups.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Grave_Rose

Hey firewalled,

 

From what I understand of Windows and NBT, the broadcasts for Workgroups won't leave a subnet so as long as your VLANs are independent links (which they have to be), they won't see each other. If you want to access them by name, you'll need a DNS server or you'll have to manually create hosts files on each box.

 

Hope this helps,

 

Sean (Gr@ve_Rose)

Site: https://tcpdump101.com Twitter: https://twitter.com/Grave_Rose Reddit: https://reddit.com/r/tcpdump101 Discord: https://discordapp.com/invite/2MZCqn6
sw2090
SuperUser
SuperUser

this is not a vlan issue - it is a dns issue. You will need a DNS Server that can resolve all the computer names.

We have an AD here and our AD Controller acts as DNS and resoves the name of any client in any subnet in any shop and so I can ping it.

 

Thus I am unsure about browsing workgroups....

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
haithm
New Contributor

sorry ,

you have created 4 vlan interfaces on your fortigate 90d. you can ping all the computers from different vlans.

 

 i created all cnofiguration for vlans and i can ping to the gateway for each vlan 

but i can not pin to computers what is the problem   please can you explain what are you done .

thank you 

 i'm so sorry , 

sw2090

well to enable inter-vlan-traffic so you can ping any host in any vlan from any other you need to set up the corresponding policies. You do not need to set up static routes. Routing is already there because of the vlan interfaces.

If there is no policy that matches your traffic it will hit policy #0 which is always the last policy in the list and matches all traffic and denies it.  So unless your traffic from one vlan to annother hits annother policy it will be denied!

 

With setting up Policies keep in mind that in FortiOS Policies are first come first server from top down. So the first policy that matches your traffic will "win" and the rest will not come to effect.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Leen
New Contributor III

Netbios uses broadcast, setup multi cast between your vlans and they all will see each other. you might have to enable this feature first to be able to do this.

You have to do the same for devices like apple TV if your itunes server is on a different subnet.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors