Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vdp
New Contributor

stealth bridge to filter traffic within same LAN segment

Hi,

 

I'm new to Fortigate, and I'd like to set up a really simple bridge.

Suppose I have a LAN switch with hosts within 192.168.0.1-10. I then connect a Fortigate between this switch and another. On the second switch I have hosts 192.168.0.11-20.

I want these two groups of hosts to be able to connect to each other through the Fortigate (so I can see all sessions).

So imagine I connect switch1 to port WAN1 or LAN Port 1 on the Fortigate, and  switch 2 to WAN2 or LAN Port 2 (whichever).

I then add IPv4 policies so I "accept all" traffic:

1) from WAN1 to WAN2

2) from WAN2 to WAN1

3) from Port1 to Port2

4) from Port2 to Port1

 

I also want to configure the management interface with IP addr. 10.1.1.1/16. It is physically connected to another switch/network.

 

I supposedly have it all configured, but I see no traffic flowing between both interfaces (WAN* or Port*).

 

Can anyone please give me some genral pointers (or CLI commands) to make this happen?

It basically needs to be a transparent bridge within the same suibnet so I can analyze/filter traffic.

 

Thanks,

 

Vieri

 

[EDIT] Please find attached several screenshots. WAN1, WAN2, Port1 and Port2 are configured alike. I would like to bridge any set of WAN1+WAN2 or port1+port2. Then simply monitor traffic flowing within this or these bridge/s.

 

[EDIT] Virtual Wire Pair... is that the way to go?

 

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors