Skip to main content

Configure VLAN

Last update:

Virtual Local Area Networks (VLANs) allow you to segment your network, maximize performance, and provide additional network security.

The settings in the instructions apply to FortiOS 6.x and 7.x versions. If you have a different version of FortiOS, you can find documentation for that version in the FortiGate control panel in the upper right corner or on the official FortiGate website.

To create two virtual networks with access to each other and to the Internet:

  1. Create network interfaces.
  2. Customize the security policy.

Create network interfaces

  1. Connect to the firewall.

  2. Click the NetworkInterfaces tab.

  3. Specify the interface name.

  4. In the Type field, select the value - VLAN.

  5. In the VLAN ID field, specify the network ID.

  6. In the Role field, select the value - LAN.

  7. In the IP/Netmask field, specify the IP address and subnet mask for the VLAN.

  8. Click OK.

  9. Repeat steps 1-8 to create a second network interface.

  10. Go to Policy & ObjectsAddresses.

  11. Click Create new.

Customize the security policy

  1. Go to Policy & ObjectsIPv4 Policy and create a new policy.

  2. In the Incoming Interface field, select the first VLAN.

  3. In the Outgoing Interface field, select the second VLAN.

  4. In the Source field, select the address of the first VLAN.

  5. In the Destination field, select the address of the second VLAN.

  6. Make sure that NAT is disabled in the policy.

  7. Repeat steps 1-6 to create a second policy. Swap the first and second VLANs in the policy.

  8. Go to Policy & ObjectsIPv4 Policy and create a new policy.

  9. In Incoming Interface, select the first VLAN.

  10. In Outgoing Interface, select the external interface.

  11. In Source, select the address of the first VLAN.

  12. In Destination, select the address of the external interface.

  13. Repeat steps 8-12 to create a policy for the second VLAN.