12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

System Network<br />

VLANs in Transparent mode<br />

To add a VLAN subinterface in Transparent mode<br />

The VLAN ID of each VLAN subinterface must match the VLAN ID added by the<br />

IEEE 802.1Q-<strong>com</strong>pliant router or switch. The VLAN ID can be any number<br />

between 1 and 4096. You add VLAN subinterfaces to the physical interface that<br />

receives VLAN-tagged packets.<br />

Note: A VLAN must not have the same name as a virtual domain or zone.<br />

1 Go to System > Network > Interface.<br />

2 Select Create New to add a VLAN subinterface.<br />

3 Enter a Name to identify the VLAN subinterface.<br />

4 Select the physical interface that receives the VLAN packets intended for this<br />

VLAN subinterface.<br />

5 Enter the VLAN ID that matches the VLAN ID of the packets to be received by this<br />

VLAN subinterface.<br />

6 Select which virtual domain to add this VLAN subinterface to.<br />

See “Using virtual domains” on page 71 for information about virtual domains.<br />

7 Configure the administrative access, and log settings as you would for any<br />

<strong>FortiGate</strong> interface.<br />

See “Interface settings” on page 83 for more descriptions of these settings.<br />

8 Select OK to save your changes.<br />

The <strong>FortiGate</strong> unit adds the new subinterface to the interface that you selected.<br />

9 Select Bring up to start the VLAN subinterface.<br />

To add firewall policies for VLAN subinterfaces<br />

Once you have added VLAN subinterfaces you can add firewall policies for<br />

connections between VLAN subinterfaces or from a VLAN subinterface to a<br />

physical interface.<br />

1 Go to Firewall > Address.<br />

2 Select Create New to add firewall addresses that match the source and<br />

destination IP addresses of VLAN packets.<br />

See “About firewall addresses” on page 289.<br />

3 Go to Firewall > Policy.<br />

4 Add firewall policies as required.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 113

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!