Configure VLAN
Virtual Local Area Networks (VLANs) allow you to segment a network, increase performance, and provide additional network security.
The settings in this guide are relevant for FortiOS versions 6.x and 7.x. If you have a different version of FortiOS, you can find the documentation for it in the FortiGate control panel in the upper right corner or on the official FortiGate website.
To create two virtual networks with access to each other and the internet:
Create network interfaces
Graphical interface
CLI
FortiOS 6.x
FortiOS 7.x
-
Go to the Network → Interfaces tab.
-
Specify the interface name.
-
In the Type field, select — VLAN.
-
In the VLAN ID field, specify the network identifier.
-
In the Role field, select — LAN.
-
In the IP/Netmask field, specify the IP address and subnet mask for the VLAN.
-
Click OK.
-
Repeat steps 1—8 to create the second network interface.
-
Go to the Policy & Objects → Addresses section.
-
Click Create new.
Configure the security policy
Graphical interface
CLI
-
Go to the Policy & Objects → IPv4 Policy section and create a new policy.
-
In the Incoming Interface field, select the first VLAN.
-
In the Outgoing Interface field, select the second VLAN.
-
In the Source field, select the address of the first VLAN.
-
In the Destination field, select the address of the second VLAN.
-
Make sure that NAT is disabled in the policy.
-
Repeat steps 1–6 to create the second policy. In this policy, swap the first and second VLANs.
-
Go to the Policy & Objects → IPv4 Policy section and create a new policy.
-
In Incoming Interface, select the first VLAN.
-
In Outgoing Interface, select the external interface.
-
In Source, select the address of the first VLAN.
-
In Destination, select the address of the external interface.
-
Repeat steps 8–12 to create a policy for the second VLAN.