Skip to main content
Configure VLAN
Last update:

Configure VLAN

Virtual Local Area Networks (VLANs) allow you to segment your network, maximize performance, and provide additional network security.

To create two virtual networks with access to each other and to the Internet:

  1. Create interfaces.
  2. Configure security policy.

Create interfaces

  1. Click the Network → Interfaces tab.
  2. Specify a name for the new interface.
  3. Select VLAN for Type.
  4. Set the network ID in the VLAN ID field.
  5. Select LAN for Role.
  6. In the IP/Netmask field, set the network address and mask.
  7. Add addresses for the created VLANs. To do this, go to Policy & ObjectsAddresses.
  8. Create a new address and specify its name and IP address. In recent versions of FortiOS firmware, these addresses are created automatically when VLAN interfaces are created.

Customize security policy

Create two policies for VLAN subnets to access each other. In these policies, make sure that NAT is enabled.

  1. Go to Policy & ObjectsIPv4 Policy and create a new policy.
  2. Select the interface of the first VLAN as the Incoming Interface and the interface of the second VLAN as the Outgoing Interface.
  3. Select the address of the first VLAN as Source and the address of the second VLAN as Destination.
  4. Make sure that NAT is turned off.
  5. Create a second policy, but swap the VLANs.
  6. Create two policies for each VLAN subnet for Internet access similar to the previous ones, but select the external interface as the Outgoing Interface.