colly72 Posted October 1, 2013 Posted October 1, 2013 OK, here's the requirement. I have a Netgear GS748T switch in one cabinet and an HP Procurve 1810G switch in another - I want to setup 2 VLANs - one for the academic network and one for accounts. In addition I have a Fortigate 80C which is used as a perimeter UTM device but can also act as an L3 router. I need the accounts PCs which are connected to the Procurve to be able to connect to the academic VLAN but the academic PCs (connected to the Netgear switch) not to be able to access the Accounts VLAN. I'm assuming that I can use the Fortigate as an L3 router to enable inter VLAN routing but I'm unsure where to start, or even if it's possible/desirable to have HP and Netgear setup in this way. Can anyone give me some pointers or basic setup instructions? Thanks in advance.
Davit2005 Posted October 1, 2013 Posted October 1, 2013 Your better off using a Layer 3 switch to do InterVlan routing TBH rather than a router. My preference would be a HP layer 3 and get rid of the Netgear.
colly72 Posted October 1, 2013 Author Posted October 1, 2013 Thanks for the reply. I know that a Layer 3 switch would be the preferred option but from a financial perspective, it's a luxury I don't have, I need to try and make it all work with the hardware we already have. Can it be done?
AngryTechnician Posted October 1, 2013 Posted October 1, 2013 (edited) What you're describing is going to be difficult to achieve on your networking hardware. You can't easily set up 1-way access between VLANs as traffic has to be able to pass from Academic > Accounts in order for the Accounts machines to receive any replies to requests for data. If the Fortinet has sufficiently advanced firewalling capability (i.e. it does stateful packet inspection) you could probably get it working, but if I were looking at doing something like this I'd be investigating whether I could do it using Windows Firewall on the Accounts PCs. Edited October 1, 2013 by AngryTechnician
colly72 Posted October 2, 2013 Author Posted October 2, 2013 After looking into this a bit more, I'm sure that the Fortigate can be used to achieve this, with a combination of VLANs and VDOMs, which effectively split the Fortigate into 2 distinct devices and apply firewall and routing rules based on that, to set the traffic up as required. Has anyone used VDOMS effectively to achieve a similar outcome?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now