Skip to main content

Configure VLAN

Last update:

Virtual Local Area Networks (VLANs) allow you to segment a network, increase performance, and provide additional network security.

The settings in this guide are relevant for FortiOS versions 6.x and 7.x. If you have a different version of FortiOS, you can find the documentation for it in the FortiGate control panel in the upper right corner or on the official FortiGate website.

To create two virtual networks with access to each other and the internet:

  1. Create network interfaces.
  2. Configure the security policy.

Create network interfaces

  1. Connect to the firewall.

  2. Go to the NetworkInterfaces tab.

  3. Specify the interface name.

  4. In the Type field, select — VLAN.

  5. In the VLAN ID field, specify the network identifier.

  6. In the Role field, select — LAN.

  7. In the IP/Netmask field, specify the IP address and subnet mask for the VLAN.

  8. Click OK.

  9. Repeat steps 1—8 to create the second network interface.

  10. Go to the Policy & ObjectsAddresses section.

  11. Click Create new.

Configure the security policy

  1. Go to the Policy & ObjectsIPv4 Policy section and create a new policy.

  2. In the Incoming Interface field, select the first VLAN.

  3. In the Outgoing Interface field, select the second VLAN.

  4. In the Source field, select the address of the first VLAN.

  5. In the Destination field, select the address of the second VLAN.

  6. Make sure that NAT is disabled in the policy.

  7. Repeat steps 1–6 to create the second policy. In this policy, swap the first and second VLANs.

  8. Go to the Policy & ObjectsIPv4 Policy section and create a new policy.

  9. In Incoming Interface, select the first VLAN.

  10. In Outgoing Interface, select the external interface.

  11. In Source, select the address of the first VLAN.

  12. In Destination, select the address of the external interface.

  13. Repeat steps 8–12 to create a policy for the second VLAN.