12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

System Network<br />

VLANs in NAT/Route mode<br />

Figure 45 shows a simplified NAT/Route mode VLAN configuration. In this<br />

example, the <strong>FortiGate</strong> internal interface connects to a VLAN switch using an<br />

802.1Q trunk and is configured with two VLAN subinterfaces (VLAN 100 and<br />

VLAN 200). The external interface connects to the Internet. The external interface<br />

is not configured with VLAN subinterfaces.<br />

When the VLAN switch receives packets from VLAN 100 and VLAN 200, it applies<br />

VLAN tags and forwards the packets to local ports and across the trunk to the<br />

<strong>FortiGate</strong> unit. The <strong>FortiGate</strong> unit is configured with policies that allow traffic to<br />

flow between the VLANs and from the VLANs to the external network.<br />

Figure 56: <strong>FortiGate</strong> unit in NAT/Route mode<br />

Internet<br />

Untagged packets<br />

External 172.16.21.2<br />

<strong>FortiGate</strong> unit<br />

Internal 192.168.110.126<br />

802.1Q<br />

trunk<br />

Fa 0/24<br />

Fa 0/3<br />

Fa 0/9<br />

VLAN 100 VLAN Switch<br />

VLAN 200<br />

VLAN 100 Network<br />

10.1.1.0<br />

VLAN 200 Network<br />

10.1.2.0<br />

Adding VLAN subinterfaces<br />

The VLAN ID of each VLAN subinterface must match the VLAN ID added by the<br />

IEEE 802.1Q-<strong>com</strong>pliant router. The VLAN ID can be any number between 1 and<br />

4096. Each VLAN subinterface must also be configured with its own IP address<br />

and netmask.<br />

Note: A VLAN must not have the same name as a virtual domain or zone.<br />

You add VLAN subinterfaces to the physical interface that receives VLAN-tagged<br />

packets.<br />

To add a VLAN subinterface in NAT/Route mode<br />

1 Go to System > Network > Interface.<br />

2 Select Create New to add a VLAN subinterface.<br />

3 Enter a Name to identify the VLAN subinterface.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 109

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!