Тёмный

Configuring VLAN and Inter-vlan routing on Fortigate firewall 

Techy-World
Подписаться 1,1 тыс.
Просмотров 34 тыс.
50% 1

Fortigate VLAN and Inter-VLAN configuration.
This video shows the steps to configure vlan and firewall policy that allows inter-vlan communication.

Опубликовано:

 

15 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 48   
@techy-world3716
@techy-world3716 Месяц назад
Please like, Share this videos to encourage more training videos. Thanks
@Scolaratari
@Scolaratari Год назад
This saved my ass because I was tasked to setup 4 vlans in our office using a 100E, will be creating 4 ports with 4 subnets and setup routing between them. very useful thank you!
@techy-world3716
@techy-world3716 Год назад
I am very happy it was helpful.
@Neur0bit
@Neur0bit Год назад
Great video. BTW, you can save time by just creating one policy for the inter-vlan portion. Just create the first one, and then once done, right click on that policy and clone-reverse. It will recreate it in the opposite direction. All you have to do is give its a name. Cheers
@techy-world3716
@techy-world3716 Год назад
You're absolutely right! Nevertheless, I'm well acquainted with the concept of clone reverse. In my opinion, individuals ought to grasp the process of creating things from the ground up. Once they have a solid grasp of the fundamentals, they can gradually acquaint themselves with the more straightforward approaches to accomplishing tasks.
@bounseysinnavong3963
@bounseysinnavong3963 Месяц назад
Very good, Is there any configuration for beginners?
@techy-world3716
@techy-world3716 Месяц назад
I recommend you watch this video ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-ac1L9ApwLlk.html
@azeem20090
@azeem20090 8 месяцев назад
is there any need to have policy between one vlan in firewall?
@techy-world3716
@techy-world3716 8 месяцев назад
No there is no need to have policy between VLAN but there are reasons to why you may want someone to have access to a specific VLAN other than where they belong. For example if you have a Camera VLAN and you belong to Data VLAN you won't be able to view the camera from your network device in Data VLAN without having a policy to allow your device or the entire Data VLAN. I hope this helps
@mayarmalongmajokamaach5853
@mayarmalongmajokamaach5853 2 месяца назад
very good video Sir.
@maurofadda289
@maurofadda289 3 месяца назад
the LAN 2 network is basically the management,right?Great video
@techy-world3716
@techy-world3716 3 месяца назад
LAN 2 network has some management features, such as HTTPS or FMG. Once any of the Administrative Access is enabled on that interface that makes it a management interface.
@yvesneptune
@yvesneptune 4 месяца назад
Can I configure IP addresses on both the physical interface and VLAN interface as router on a stick. And reach the physical interface on a switch that has a port in Access mode???
@techy-world3716
@techy-world3716 4 месяца назад
The answer is Yes. You can configure multiple physical and Virtual interfaces and even route between them. What you need is policy. To answer your question YES it is possible
@naveedhamid9044
@naveedhamid9044 Год назад
i have a 80F fortigate and an aruba 1830 switch..is it possible to communicate vlan info between the these devices.
@techy-world3716
@techy-world3716 Год назад
Absolutely. The FortiGate firewall VLAN communicate easily with any managed switch, Cisco, Aruba, HP, Unifi and many more.
@xlv600tr
@xlv600tr Месяц назад
Hi. Thank you for video. I am not able to make ito work yet but there are the concept. I keep trying on my 60F ando managed Zyxel switch...
@techy-world3716
@techy-world3716 28 дней назад
@@xlv600tr Tell me exactly where you need support. I can give you some pointers
@xlv600tr
@xlv600tr 28 дней назад
@@techy-world3716 thank you so much! I made 2 VLAN on FortiGate 60F (VLAN 10 and VLAN 25) using a a Zyxel GS1900 managed switch in testing enviroment. If I configure clients with fixed IP it works, but they aren't able to get IP from DHCP server ( configured on eachFortigate vlan, 192.168.10.1/24 and 192.168.25.1/24). I don't understand if the problem is the switch that is stopping DHCP service or if there is other configuration to do on firewall.
@techy-world3716
@techy-world3716 28 дней назад
@xlv600tr If you scroll down on your VLAN 10 and VLAN 20 interfaces there, you will see the option to enable DHCP. The DHCP can be configured on your firewall, or you can configure it on your Zyxel GS1900 switch. If DHCP is configured on your switch, you will need to enable DHCP relay under the advance option below the DHCP on the fortigate 60F firewall.
@xlv600tr
@xlv600tr 28 дней назад
@@techy-world3716 Thank you again. In switch menu I find only if switch receive ip from dhcp or if it has to fixed (for management). On fw it is active on both VLANS
@KernelKrunch663
@KernelKrunch663 27 дней назад
Very good
@psksuresh8800
@psksuresh8800 Месяц назад
Maximum number of entries has been reached. Object set operator error, -4 discard the setting. This error comming,plz support
@techy-world3716
@techy-world3716 Месяц назад
This error is due to a trial license you are using which only allow 4 interfaces. What you can do is to use 2 interface (1 for WAN and the other for LAN which will include VLAN sub interfaces)
@techy-world3716
@techy-world3716 Месяц назад
This video will show you how to remove interfaces ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-jCJLwmfP0uM.html
@manoranjanmahanta1563
@manoranjanmahanta1563 8 месяцев назад
After doing this i am not able to access the firewall from lan zone. So how to get access it.
@techy-world3716
@techy-world3716 8 месяцев назад
The access will be applied to the LAN interface e.g port 1 if you are using physical port or the VLAN interface e.g Data VLAN. You can also apply it to multiple interface but not on the zone.
@manoranjanmahanta1563
@manoranjanmahanta1563 8 месяцев назад
Yes, I have created a data vlan 10 under port 1 and i am trying to access it from vlan 10 interface also https is enabled on that interface.
@techy-world3716
@techy-world3716 8 месяцев назад
Have you lost all access to the device or can you get in via console or ssh?
@techy-world3716
@techy-world3716 8 месяцев назад
The device you are accessing it from must be in VLAN 10 subnet as well. That is very important
@techy-world3716
@techy-world3716 8 месяцев назад
If you are still having issue, I can look at in over a remote session if you want.
@glenntembo2693
@glenntembo2693 Год назад
Good video and explanation but use a diagram for the self-paced bro- that way you get likes - someone who knows this will either ignore or just like. Thanks
@techy-world3716
@techy-world3716 Год назад
Noted
@jonjon5332
@jonjon5332 Год назад
excelente
@tamoorali9065
@tamoorali9065 11 месяцев назад
where is the live testing you did not connect anything and test anything or live anything
@techy-world3716
@techy-world3716 8 месяцев назад
Point taken, I will ensure that I show more testing in my next videos. But be assured that these steps are what is required on the FortiGate.
@psksuresh8800
@psksuresh8800 Месяц назад
Sir I am unable to sub interface
@techy-world3716
@techy-world3716 Месяц назад
Watch between 2mins - 5mins of this video that shows how to create VLAN which is the sub interfaces you are trying to create
@psksuresh8800
@psksuresh8800 Месяц назад
Iam unable to create sub interface in fortigate firewall, below error is coming Maximum number of entries has been reached. Object set operator error, -4 discard the setting.
@techy-world3716
@techy-world3716 Месяц назад
@@psksuresh8800 Delete 2 of your physical interfaces. You are using a trial license. You will be allowed 4 interfaces on a trial version. So best is to delete 2 physical interfaces and use 1 for WAN and the other interfaces for your sub interfaces
@psksuresh8800
@psksuresh8800 Месяц назад
Sir, how to delete interface port3
@psksuresh8800
@psksuresh8800 Месяц назад
Kindly support sir,we suffer last two weeks for this issue
@tallahassZ
@tallahassZ Год назад
well explained. good job. Dropped a LIKE.
@techy-world3716
@techy-world3716 Год назад
Much appreciated!
@tallahassZ
@tallahassZ Год назад
@@techy-world3716 and I subbed! Keep doing what you do, bro. ;-)
Далее
InterVlan routing on Fortigate Firewall | Lecture#5
14:51
Собираю Маню к осени ✨
00:48
Просмотров 946 тыс.
How to Create a Management VLAN | CCST | CCNA | CCNP
7:56
Fortinet: Getting Started with a FortiGate Firewall
9:46
Virtualizing Fortigate firewall on Proxmox
44:33
Просмотров 3,5 тыс.
Собираю Маню к осени ✨
00:48
Просмотров 946 тыс.