Professional Documents
Culture Documents
VLAN
VLAN
• Allows to create a lot of networks (Virtual Networks) on the same Switch (Physical Switch).
• A zone is created "Interface" that you assign other interfaces too (Physical, VLAN..).
• Zone is a group of 1 or more interfaces that you can apply security policy to control traffic.
Previous
Next
Creating a firewall policy for the zone
1. Go to Policy & Objects > IPv4 Policy and create a firewall policy giving any VLAN in the LAN
Zone permission to access the Internet.
2. Set up Security Profiles according to your organization's requirements.
VDOM configuration
virtual domains (VDOMs) to provide Internet access for two different companies (called Company
A and Company B) using a single FortiGate.
o Destination: 172.16.1.0/255.255.255.0
o Interface: Accounting-Sales
o Gateway: 10.10.10.2
Incoming:
o Incoming: AS0
o Outgoing: Port2
o NAT Disable
o Destination: 172.16.1.0/255.255.255.0
o Interface: AS1
o Gateway: 10.10.10.1
o Incoming: AS1
o Outgoing: Port3
o NAT Disable
Figure 8.33: Create a Firewall Policy in Sales VDOM from AS1 to Port3
11. Now, you should verify your configuration and should be able to ping from
WebTerm1 to WebTerm2.
Figure 8.34: Verify configuration
You must use either the prof_admin or a custom profile for per-VDOM administrators.
3. Remove the root VDOM from the Virtual Domains list and add VDOM-A.
4. Repeat the above steps to create a per-VDOM administrator for VDOM-B.
1. Access VDOM-A using the dropdown menu located in the top-left corner.
2. To add a static route, go to Network > Static Routes and select Create New.
3. Set Destination to Subnet and leave the destination IP address set to 0.0.0.0/0.0.0.0.
4. Set Gateway to the IP address provided by your ISP and Interface to the Internet-facing
interface.
5. To create a new policy, go to Policy & Objects > IPv4 Policy and select Create New.
6. Set the Incoming Interface to port 1 and set the Outgoing Interface to wan 1.
7. Repeat the above steps to configure VDOM-B.
Link Aggregation combines multiple physical interfaces into a single aggregated or logical
interface, providing increased BW as well as link redundancy 5through the Protocol LACP.
Limitations :
A desired name can be specified in the Interface Name section on the screen
that opens. Select 802.3ad Aggregate from the Type field.
In the Interface Members field, the ports that will be included in LACP are
selected. The role of the interface created from the Tags field is
determined. Depending on the usage needs, LAN, WAN, DMZ can be
selected. The network of the created interface is determined from the
address. If you want to access the device via these ports, access methods are
selected from the Administrative Access field.
On Switch
• SW :
ena
conf t
hostname SW
int range gi 0/0 - 1
channel-group 1 mode active
exit
do wr