12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

System Network<br />

VLANs in Transparent mode<br />

If the network uses IEEE 802.1 VLAN tags to segment your network traffic, you<br />

can configure a <strong>FortiGate</strong> unit operating in Transparent mode to provide security<br />

for network traffic passing between different VLANs. To support VLAN traffic in<br />

Transparent mode, you add virtual domains to the <strong>FortiGate</strong> unit configuration. A<br />

virtual domain consists of two or more VLAN subinterfaces or zones. In a virtual<br />

domain, a zone can contain one or more VLAN subinterfaces.<br />

When the <strong>FortiGate</strong> unit receives a VLAN tagged packet at an interface, the<br />

packet is directed to the VLAN subinterface with matching VLAN ID. The VLAN<br />

subinterface removes the VLAN tag and assigns a destination interface to the<br />

packet based on its destination MAC address. The firewall policies for this source<br />

and destination VLAN subinterface pair are applied to the packet. If the packet is<br />

accepted by the firewall, the <strong>FortiGate</strong> unit forwards the packet to the destination<br />

VLAN subinterface. The destination VLAN ID is added to the packet by the<br />

<strong>FortiGate</strong> unit and the packet is sent to the VLAN trunk.<br />

Note: There is a maximum of 255 interfaces total allowed per VDOM in Transparent mode.<br />

This includes VLANs. If no other interfaces are configured for a VDOM, you can configure<br />

up to 255 VLANs in that VDOM.<br />

Figure 57: <strong>FortiGate</strong> unit with two virtual domains in Transparent mode<br />

<strong>FortiGate</strong> unit<br />

VLAN1<br />

VLAN2<br />

VLAN3<br />

VLAN Switch<br />

or router<br />

Internal<br />

VLAN1<br />

VLAN2<br />

VLAN3<br />

VLAN<br />

trunk<br />

root virtual domain<br />

VLAN1<br />

VLAN1<br />

New virtual domain<br />

VLAN2<br />

VLAN2<br />

VLAN3<br />

VLAN3<br />

External<br />

VLAN1<br />

VLAN2<br />

VLAN3<br />

VLAN<br />

trunk<br />

VLAN Switch<br />

or router<br />

Internet<br />

Figure 58 shows a <strong>FortiGate</strong> unit operating in Transparent mode and configured<br />

with three VLAN subinterfaces. In this configuration the <strong>FortiGate</strong> unit could be<br />

added to this network to provide virus scanning, web content filtering, and other<br />

services to each VLAN.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 111

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!