Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

local proxy arp - isolated/protected ports

Hello all! Sorry about the topic - I just couldn' t think of a better description. I' m looking to use a 110c in a hosting environment (all customers in a single vlan/subnet). So I want to isolate all customer ports from eachother (cisco switches, so I' m just going to use " switchport protected" ) However, we will need to have the possibility to allow traffic between certain hosts, should the need arise. In cisco-speak I would enable " local proxy arp" so that the router(fortigate in this case) would respond to all arp requests with it' s own mac address, thereby allowing me to " route" traffic between hosts on the same subnet. Is there any way to do this on a fortigate?
1 REPLY 1
abelio
SuperUser
SuperUser

Hello and welcome to forum, use Virtual IPs. Textually from admin guide " Virtual IPs use proxy ARP, as defined in RFC 1027, so that the FortiGate unit can respond to ARP requests on a network for a server that is actually installed on another network." Also, if you want to add entries to the proxy arp table you can use CLI command: " config system proxy-arp"
I' m looking to use a 110c in a hosting environment (all customers in a single vlan/subnet). So I want to isolate all customer ports from eachother (cisco switches, so I' m just going to use " switchport protected" )
another approach could be assign an individual vlan for customer and manage traffic between vlans. regards,

regards




/ Abel

regards / Abel
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors