- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
inter-VLAN routing issue
Hi Team,
I have FG FW 601E, and I am facing the below issue on that FW, Please help me to resolve the same.
In my FW, I have multiple VLAN interfaces, and on those interfaces, incoming traffic for a particular IP is on one interface, and outgoing traffic is on another interface, like requests via VLAN100 and responses via VLAN200.
Is it possible to redirect or reroute the traffic from one interface to another? or any other solution apart from enabling asymmetric routing?
Regards,
Thoubik Ahamed P.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Thoubik ,
As far as i understand you have topology like this :
VLAN100<-->Fortigate<-->VLAN200
Withoyt asymetric routing you can route the traffic from VLAN100 to VLAN200 or vica versa , you just need to configure proper FW rules and adjust the routing if the source/destinations are not directly connected to Fortigate.
Best regards,
Fortinet
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Thoufik
I think you should try auxiliary sessions before asymmetric routing, as it is cleaner and more secure.
You just need to add a route defined on VLAN200 towards the target subnet.
Please check the below docs for more info.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why do you need to do that? You're saying like a ping packet to the FGT is coming from 10.10.10.10 into VLAN100 but the ping reply to 10.10.10.10 needs to go out VLAN200.
Or are you saying the packets are just passing through the FGT, requests are coming from a and going out b, and replies are coming back from b and going out a?
Toshi
