12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

VLANs in Transparent mode<br />

System Network<br />

4 Select the physical interface that receives the VLAN packets intended for this<br />

VLAN subinterface.<br />

5 Enter the VLAN ID that matches the VLAN ID of the packets to be received by this<br />

VLAN subinterface.<br />

6 If you are the super admin, select the virtual domain to add this VLAN subinterface<br />

to. Otherwise, you can only create VLAN subinterfaces in your own VDOM.<br />

See “Using virtual domains” on page 71 for information about virtual domains.<br />

7 Configure the VLAN subinterface settings as you would for any <strong>FortiGate</strong><br />

interface.<br />

See “Interface settings” on page 83.<br />

8 Select OK to save your changes.<br />

The <strong>FortiGate</strong> unit adds the new VLAN subinterface to the interface that you<br />

selected in step 4.<br />

To add firewall policies for VLAN subinterfaces<br />

Once you have added VLAN subinterfaces you can add firewall policies for<br />

connections between VLAN subinterfaces or from a VLAN subinterface to a<br />

physical interface.<br />

1 Go to Firewall > Address.<br />

2 Select Create New to add firewall addresses that match the source and<br />

destination IP addresses of VLAN packets.<br />

See “About firewall addresses” on page 289.<br />

3 Go to Firewall > Policy.<br />

4 Create or add firewall policies as required.<br />

VLANs in Transparent mode<br />

In Transparent mode, the <strong>FortiGate</strong> unit can apply firewall policies and services,<br />

such as authentication, protection profiles, and other firewall features, to traffic on<br />

an IEEE 802.1 VLAN trunk. You can insert the <strong>FortiGate</strong> unit operating in<br />

Transparent mode into the trunk without making changes to your network. In a<br />

typical configuration, the <strong>FortiGate</strong> internal interface accepts VLAN packets on a<br />

VLAN trunk from a VLAN switch or router connected to internal VLANs. The<br />

<strong>FortiGate</strong> external interface forwards tagged packets through the trunk to an<br />

external VLAN switch or router which could be connected to the Internet. The<br />

<strong>FortiGate</strong> unit can be configured to apply different policies for traffic on each VLAN<br />

in the trunk.<br />

For VLAN traffic to be able to pass between the <strong>FortiGate</strong> Internal and external<br />

interface you would add a VLAN subinterface to the internal interface and another<br />

VLAN subinterface to the external interface. If these VLAN subinterfaces have the<br />

same VLAN IDs, the <strong>FortiGate</strong> unit applies firewall policies to the traffic on this<br />

VLAN. If these VLAN subinterfaces have different VLAN IDs, or if you add more<br />

than two VLAN subinterfaces, you can also use firewall policies to control<br />

connections between VLANs.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

110 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!