Fortigate Units And Vlans - Fortinet FortiGate FortiGate-500 Administration Manual

Fortinet fortigate fortigate-500: user guide
Hide thumbs Also See for FortiGate FortiGate-500:
Table of Contents

Advertisement

System network

FortiGate units and VLANs

FortiGate-500 Administration Guide
Figure 14: Basic VLAN topology
VLAN 1 network
In a typical VLAN configuration, 802.1Q-compliant VLAN layer-2 switches or layer-3
routers or firewalls add VLAN tags to packets. Packets passing between devices in
the same VLAN can be handled by layer 2 switches. Packets passing between
devices in different VLANs must be handled by a layer 3 device such as router,
firewall, or layer 3 switch.
Using VLANs, a single FortiGate unit can provide security services and control
connections between multiple security domains. Traffic from each security domain is
given a different VLAN ID. The FortiGate unit can recognize VLAN IDs and apply
security policies to secure network and IPSec VPN traffic between security domains.
The FortiGate unit can also apply authentication, protection profiles, and other firewall
policy features for network and VPN traffic that is allowed to pass between security
domains.
01-28006-0007-20041105
Internet
Untagged
packets
Firewall or
Esc
Enter
VLAN trunk
VLAN 1
VLAN 2
POWER
VLAN 2
VLAN 1
VLAN overview
Router
VLAN Switch or router
VLAN 2 network
63

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents